5
CVSSv2

CVE-2007-2637

Published: 13/05/2007 Updated: 29/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

MoinMoin prior to 20070507 does not properly enforce ACLs for calendars and includes, which allows remote malicious users to read certain pages via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

moinmoin moinmoin

Vendor Advisories

A flaw was discovered in MoinMoin’s error reporting when using the AttachFile action By tricking a user into viewing a crafted MoinMoin URL, an attacker could execute arbitrary JavaScript as the current MoinMoin user, possibly exposing the user’s authentication information for the domain where MoinMoin was hosted (CVE-2007-2423) ...
Several remote vulnerabilities have been discovered in MoinMoin, a Python clone of WikiWiki The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-2423 A cross-site-scripting vulnerability has been discovered in attachment handling CVE-2007-2637 Access control lists for calendars and includes wer ...