4.3
CVSSv2

CVE-2012-6082

Published: 03/01/2013 Updated: 07/01/2013
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the rsslink function in theme/__init__.py in MoinMoin 1.9.5 allows remote malicious users to inject arbitrary web script or HTML via the page name in a rss link.

Vulnerable Product Search on Vulmon Subscribe to Product

moinmo moinmoin 1.9.5

Vendor Advisories

It was discovered that missing input validation in the twikidraw and anywikidraw actions can result in the execution of arbitrary code This security issue is being actively exploited This update also addresses path traversal in AttachFile For the stable distribution (squeeze), this problem has been fixed in version 193-1+squeeze4 For the unst ...