4.3
CVSSv2

CVE-2008-0780

Published: 14/02/2008 Updated: 03/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in MoinMoin 1.5.x up to and including 1.5.8 and 1.6.x prior to 1.6.1 allows remote malicious users to inject arbitrary web script or HTML via the login action.

Vulnerable Product Search on Vulmon Subscribe to Product

moinmoin moinmoin 1.5.3_rc2

moinmoin moinmoin 1.5.4

moinmoin moinmoin 1.6.0

moinmoin moinmoin 1.5.3

moinmoin moinmoin 1.5.3_rc1

moinmoin moinmoin 1.5.7

moinmoin moinmoin 1.5.8

moinmoin moinmoin 1.5.0

moinmoin moinmoin 1.5.1

moinmoin moinmoin 1.5.2

moinmoin moinmoin 1.5.5a

moinmoin moinmoin 1.5.6

moinmoin moinmoin 1.5.5

moinmoin moinmoin 1.5.5_rc1

Vendor Advisories

Fernando Quintero discovered than MoinMoin did not properly sanitize its input when processing login requests, resulting in cross-site scripting (XSS) vulnerabilities With cross-site scripting vulnerabilities, if a user were tricked into viewing server output during a crafted server request, a remote attacker could exploit this to modify the conte ...
Several remote vulnerabilities have been discovered in MoinMoin, a Python clone of WikiWiki The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-2423 A cross-site-scripting vulnerability has been discovered in attachment handling CVE-2007-2637 Access control lists for calendars and includes wer ...