Записи moinmo
26 опубликованных записей вендора moinmo.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 3,8 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-264 Permissions, Privileges, and Access Controls4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-16 Configuration1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-862 Missing Authorization1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
26 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2020-25074Эксплойта нет | The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request.moinmo · moinmoin · CWE-22 | Критическая9,8 | — | 6,6 % | 10 нояб. 2020 г. |
35Наблюдать | CVE-2012-6081Готовый эксплойт | Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actmoinmo · moinmoin | Средняя6,0 | — | 35,3 % | 2 янв. 2013 г. |
31Наблюдать | CVE-2009-4762Эксплойта нет | MoinMoin 1.7.x before 1.7.3 and 1.8.x before 1.8.3 checks parent ACLs in certain inappropriate circumstances during processing of hierarchicmoinmo · moinmoin · CWE-264 | Высокая7,5 | — | 3,1 % | 29 мар. 2010 г. |
31Наблюдать | CVE-2010-0717Эксплойта нет | The default configuration of cfg.packagepages_actions_excluded in MoinMoin before 1.8.7 does not prevent unsafe package actions, which has umoinmo · moinmoin · CWE-16 | Высокая7,5 | — | 2,0 % | 26 февр. 2010 г. |
31Наблюдать | CVE-2010-0669Эксплойта нет | MoinMoin before 1.8.7 and 1.9.x before 1.9.2 does not properly sanitize user profiles, which has unspecified impact and attack vectors.moinmo · moinmoin | Высокая7,5 | — | 1,9 % | 26 февр. 2010 г. |
30Наблюдать | CVE-2012-6495Proof of concept | Multiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions moinmo · moinmoin · CWE-22 | Средняя6,0 | — | 18,7 % | 2 янв. 2013 г. |
28Наблюдать | CVE-2010-0668Эксплойта нет | Unspecified vulnerability in MoinMoin 1.5.x through 1.7.x, 1.8.x before 1.8.7, and 1.9.x before 1.9.2 has unknown impact and attack vectors,moinmo · moinmoin | Средняя6,8 | — | 2,2 % | 26 февр. 2010 г. |
27Наблюдать | CVE-2008-6603Эксплойта нет | MoinMoin 1.6.2 and 1.7 does not properly enforce ACL checks when acl_hierarchic is set to True, which might allow remote attackers to bypassmoinmo · moinmoin · CWE-264 | Средняя6,8 | — | 1,7 % | 3 апр. 2009 г. |
26Наблюдать | CVE-2012-6080Эксплойта нет | Directory traversal vulnerability in the _do_attachment_move function in the AttachFile action (action/AttachFile.py) in MoinMoin 1.9.3 thromoinmo · moinmoin · CWE-22 | Средняя6,4 | — | 4,1 % | 2 янв. 2013 г. |
25Наблюдать | CVE-2012-4404Эксплойта нет | security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Knomoinmo · moinmoin · CWE-264 | Средняя6,0 | — | 2,1 % | 10 сент. 2012 г. |
25Наблюдать | CVE-2017-5934Эксплойта нет | Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbimoinmo · moinmoin · CWE-79 | Средняя6,1 | — | 1,9 % | 15 окт. 2018 г. |
24Наблюдать | CVE-2016-9119Эксплойта нет | Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.8 allows remote attackers to inject arbitmoinmo · moinmoin · CWE-79 | Средняя6,1 | — | 1,5 % | 30 янв. 2017 г. |
24Наблюдать | CVE-2016-7146Эксплойта нет | MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation or crafted URL" approach, relatmoinmo · moinmoin · CWE-79 | Средняя6,1 | — | 1,2 % | 10 нояб. 2016 г. |
24Наблюдать | CVE-2016-7148Эксплойта нет | MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation" approach, related to a "Cross moinmo · moinmoin · CWE-79 | Средняя6,1 | — | 1,2 % | 10 нояб. 2016 г. |
22Наблюдать | CVE-2020-15275Эксплойта нет | malicious SVG attachment causing stored XSS vulnerability in MoinMoinmoinmo · moinmoin · CWE-79 | Средняя5,4 | — | 1,7 % | 11 нояб. 2020 г. |
21Наблюдать | CVE-2010-1238Эксплойта нет | MoinMoin 1.7.1 allows remote attackers to bypass the textcha protection mechanism by modifying the textcha-question and textcha-answer fieldmoinmo · moinmoin · CWE-264 | Средняя5,0 | — | 2,0 % | 5 апр. 2010 г. |
21Наблюдать | CVE-2010-0667Эксплойта нет | MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environmentmoinmo · moinmoin · CWE-200 | Средняя5,0 | — | 1,9 % | 26 февр. 2010 г. |
20Наблюдать | CVE-2008-6549Эксплойта нет | The password_checker function in config/multiconfig.py in MoinMoin 1.6.1 uses the cracklib and python-crack features even though they are nomoinmo · moinmoin | Средняя5,0 | — | 1,5 % | 29 мар. 2009 г. |
20Наблюдать | CVE-2008-6548Эксплойта нет | The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorizemoinmo · moinmoin · CWE-862 | Средняя5,0 | — | 1,0 % | 29 мар. 2009 г. |
18Наблюдать | CVE-2010-2487Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.7.3 and earlier, 1.8.x before 1.8.8, and 1.9.x before 1.9.3 allow remote amoinmo · moinmoin · CWE-79 | Средняя4,3 | — | 2,7 % | 5 авг. 2010 г. |
18Наблюдать | CVE-2010-2970Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.9.x before 1.9.3 allow remote attackers to inject arbitrary web script or moinmo · moinmoin · CWE-79 | Средняя4,3 | — | 2,6 % | 5 авг. 2010 г. |
18Наблюдать | CVE-2010-2969Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.7.3 and earlier, and 1.9.x before 1.9.3, allow remote attackers to inject moinmo · moinmoin · CWE-79 | Средняя4,3 | — | 2,6 % | 5 авг. 2010 г. |
18Наблюдать | CVE-2009-1482Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin 1.8.2 and earlier allow remote attackers to inject amoinmo · moinmoin · CWE-79 | Средняя4,3 | — | 2,5 % | 29 апр. 2009 г. |
18Наблюдать | CVE-2012-6082Эксплойта нет | Cross-site scripting (XSS) vulnerability in the rsslink function in theme/__init__.py in MoinMoin 1.9.5 allows remote attackers to inject armoinmo · moinmoin · CWE-79 | Средняя4,3 | — | 2,1 % | 2 янв. 2013 г. |
15Наблюдать | CVE-2010-0828Эксплойта нет | Cross-site scripting (XSS) vulnerability in action/Despam.py in the Despam action module in MoinMoin 1.8.7 and 1.9.2 allows remote authenticmoinmo · moinmoin · CWE-79 | Низкая3,5 | — | 2,3 % | 5 апр. 2010 г. |
- CVE-2020-2507441В плане
The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request.
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %moinmo · moinmoin10 нояб. 2020 г.
- CVE-2012-608135Наблюдать
Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) act
СредняяCVSS 6,0Готовый эксплойтEPSS 35 %moinmo · moinmoin2 янв. 2013 г.
- CVE-2009-476231Наблюдать
MoinMoin 1.7.x before 1.7.3 and 1.8.x before 1.8.3 checks parent ACLs in certain inappropriate circumstances during processing of hierarchic
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %moinmo · moinmoin29 мар. 2010 г.
- CVE-2010-071731Наблюдать
The default configuration of cfg.packagepages_actions_excluded in MoinMoin before 1.8.7 does not prevent unsafe package actions, which has u
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %moinmo · moinmoin26 февр. 2010 г.
- CVE-2010-066931Наблюдать
MoinMoin before 1.8.7 and 1.9.x before 1.9.2 does not properly sanitize user profiles, which has unspecified impact and attack vectors.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %moinmo · moinmoin26 февр. 2010 г.
- CVE-2012-649530Наблюдать
Multiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions
СредняяCVSS 6,0Proof of conceptEPSS 19 %moinmo · moinmoin2 янв. 2013 г.
- CVE-2010-066828Наблюдать
Unspecified vulnerability in MoinMoin 1.5.x through 1.7.x, 1.8.x before 1.8.7, and 1.9.x before 1.9.2 has unknown impact and attack vectors,
СредняяCVSS 6,8Эксплойта нетEPSS 2 %moinmo · moinmoin26 февр. 2010 г.
- CVE-2008-660327Наблюдать
MoinMoin 1.6.2 and 1.7 does not properly enforce ACL checks when acl_hierarchic is set to True, which might allow remote attackers to bypass
СредняяCVSS 6,8Эксплойта нетEPSS 2 %moinmo · moinmoin3 апр. 2009 г.
- CVE-2012-608026Наблюдать
Directory traversal vulnerability in the _do_attachment_move function in the AttachFile action (action/AttachFile.py) in MoinMoin 1.9.3 thro
СредняяCVSS 6,4Эксплойта нетEPSS 4 %moinmo · moinmoin2 янв. 2013 г.
- CVE-2012-440425Наблюдать
security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Kno
СредняяCVSS 6,0Эксплойта нетEPSS 2 %moinmo · moinmoin10 сент. 2012 г.
- CVE-2017-593425Наблюдать
Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbi
СредняяCVSS 6,1Эксплойта нетEPSS 2 %moinmo · moinmoin15 окт. 2018 г.
- CVE-2016-911924Наблюдать
Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.8 allows remote attackers to inject arbit
СредняяCVSS 6,1Эксплойта нетEPSS 1 %moinmo · moinmoin30 янв. 2017 г.
- CVE-2016-714624Наблюдать
MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation or crafted URL" approach, relat
СредняяCVSS 6,1Эксплойта нетEPSS 1 %moinmo · moinmoin10 нояб. 2016 г.
- CVE-2016-714824Наблюдать
MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation" approach, related to a "Cross
СредняяCVSS 6,1Эксплойта нетEPSS 1 %moinmo · moinmoin10 нояб. 2016 г.
- CVE-2020-1527522Наблюдать
malicious SVG attachment causing stored XSS vulnerability in MoinMoin
СредняяCVSS 5,4Эксплойта нетEPSS 2 %moinmo · moinmoin11 нояб. 2020 г.
- CVE-2010-123821Наблюдать
MoinMoin 1.7.1 allows remote attackers to bypass the textcha protection mechanism by modifying the textcha-question and textcha-answer field
СредняяCVSS 5,0Эксплойта нетEPSS 2 %moinmo · moinmoin5 апр. 2010 г.
- CVE-2010-066721Наблюдать
MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment
СредняяCVSS 5,0Эксплойта нетEPSS 2 %moinmo · moinmoin26 февр. 2010 г.
- CVE-2008-654920Наблюдать
The password_checker function in config/multiconfig.py in MoinMoin 1.6.1 uses the cracklib and python-crack features even though they are no
СредняяCVSS 5,0Эксплойта нетEPSS 1 %moinmo · moinmoin29 мар. 2009 г.
- CVE-2008-654820Наблюдать
The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorize
СредняяCVSS 5,0Эксплойта нетEPSS 1 %moinmo · moinmoin29 мар. 2009 г.
- CVE-2010-248718Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.7.3 and earlier, 1.8.x before 1.8.8, and 1.9.x before 1.9.3 allow remote a
СредняяCVSS 4,3Эксплойта нетEPSS 3 %moinmo · moinmoin5 авг. 2010 г.
- CVE-2010-297018Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.9.x before 1.9.3 allow remote attackers to inject arbitrary web script or
СредняяCVSS 4,3Эксплойта нетEPSS 3 %moinmo · moinmoin5 авг. 2010 г.
- CVE-2010-296918Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.7.3 and earlier, and 1.9.x before 1.9.3, allow remote attackers to inject
СредняяCVSS 4,3Эксплойта нетEPSS 3 %moinmo · moinmoin5 авг. 2010 г.
- CVE-2009-148218Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin 1.8.2 and earlier allow remote attackers to inject a
СредняяCVSS 4,3Эксплойта нетEPSS 3 %moinmo · moinmoin29 апр. 2009 г.
- CVE-2012-608218Наблюдать
Cross-site scripting (XSS) vulnerability in the rsslink function in theme/__init__.py in MoinMoin 1.9.5 allows remote attackers to inject ar
СредняяCVSS 4,3Эксплойта нетEPSS 2 %moinmo · moinmoin2 янв. 2013 г.
- CVE-2010-082815Наблюдать
Cross-site scripting (XSS) vulnerability in action/Despam.py in the Despam action module in MoinMoin 1.8.7 and 1.9.2 allows remote authentic
НизкаяCVSS 3,5Эксплойта нетEPSS 2 %moinmo · moinmoin5 апр. 2010 г.