4.3
CVSSv2

CVE-2009-0312

Published: 28/01/2009 Updated: 03/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the antispam feature (security/antispam.py) in MoinMoin 1.7 and 1.8.1 allows remote malicious users to inject arbitrary web script or HTML via crafted, disallowed content.

Vulnerable Product Search on Vulmon Subscribe to Product

moinmoin moinmoin 1.7.0

moinmoin moinmoin 1.8.1

Vendor Advisories

Debian Bug report logs - #513158 CVE-2009-0260: Multiple cross-site scripting vulnerabilities Package: python-moinmoin; Maintainer for python-moinmoin is Steve McIntyre <93sam@debianorg>; Source for python-moinmoin is src:moin (PTS, buildd, popcon) Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> Date: Mon ...
Fernando Quintero discovered than MoinMoin did not properly sanitize its input when processing login requests, resulting in cross-site scripting (XSS) vulnerabilities With cross-site scripting vulnerabilities, if a user were tricked into viewing server output during a crafted server request, a remote attacker could exploit this to modify the conte ...
It was discovered that the AttachFile action in moin, a python clone of WikiWiki, is prone to cross-site scripting attacks (CVE-2009-0260) Another cross-site scripting vulnerability was discovered in the antispam feature (CVE-2009-0312) For the stable distribution (etch) these problems have been fixed in version 153-12etch2 For the testing (l ...