Перейти к содержимому
Noroxi

Записи moinmo

26 опубликованных записей вендора moinmo.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
1 · 3,8 %
Pre-auth RCE
1
С записью об исправлении
100 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

26 записей
  • CVE-2020-25074
    41В плане

    The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request.

    КритическаяCVSS 9,8Эксплойта нетEPSS 7 %

    moinmo · moinmoin10 нояб. 2020 г.

  • CVE-2012-6081
    35Наблюдать

    Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) act

    СредняяCVSS 6,0Готовый эксплойтEPSS 35 %

    moinmo · moinmoin2 янв. 2013 г.

  • CVE-2009-4762
    31Наблюдать

    MoinMoin 1.7.x before 1.7.3 and 1.8.x before 1.8.3 checks parent ACLs in certain inappropriate circumstances during processing of hierarchic

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    moinmo · moinmoin29 мар. 2010 г.

  • CVE-2010-0717
    31Наблюдать

    The default configuration of cfg.packagepages_actions_excluded in MoinMoin before 1.8.7 does not prevent unsafe package actions, which has u

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    moinmo · moinmoin26 февр. 2010 г.

  • CVE-2010-0669
    31Наблюдать

    MoinMoin before 1.8.7 and 1.9.x before 1.9.2 does not properly sanitize user profiles, which has unspecified impact and attack vectors.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    moinmo · moinmoin26 февр. 2010 г.

  • CVE-2012-6495
    30Наблюдать

    Multiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions

    СредняяCVSS 6,0Proof of conceptEPSS 19 %

    moinmo · moinmoin2 янв. 2013 г.

  • CVE-2010-0668
    28Наблюдать

    Unspecified vulnerability in MoinMoin 1.5.x through 1.7.x, 1.8.x before 1.8.7, and 1.9.x before 1.9.2 has unknown impact and attack vectors,

    СредняяCVSS 6,8Эксплойта нетEPSS 2 %

    moinmo · moinmoin26 февр. 2010 г.

  • CVE-2008-6603
    27Наблюдать

    MoinMoin 1.6.2 and 1.7 does not properly enforce ACL checks when acl_hierarchic is set to True, which might allow remote attackers to bypass

    СредняяCVSS 6,8Эксплойта нетEPSS 2 %

    moinmo · moinmoin3 апр. 2009 г.

  • CVE-2012-6080
    26Наблюдать

    Directory traversal vulnerability in the _do_attachment_move function in the AttachFile action (action/AttachFile.py) in MoinMoin 1.9.3 thro

    СредняяCVSS 6,4Эксплойта нетEPSS 4 %

    moinmo · moinmoin2 янв. 2013 г.

  • CVE-2012-4404
    25Наблюдать

    security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Kno

    СредняяCVSS 6,0Эксплойта нетEPSS 2 %

    moinmo · moinmoin10 сент. 2012 г.

  • CVE-2017-5934
    25Наблюдать

    Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbi

    СредняяCVSS 6,1Эксплойта нетEPSS 2 %

    moinmo · moinmoin15 окт. 2018 г.

  • CVE-2016-9119
    24Наблюдать

    Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.8 allows remote attackers to inject arbit

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    moinmo · moinmoin30 янв. 2017 г.

  • CVE-2016-7146
    24Наблюдать

    MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation or crafted URL" approach, relat

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    moinmo · moinmoin10 нояб. 2016 г.

  • CVE-2016-7148
    24Наблюдать

    MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation" approach, related to a "Cross

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    moinmo · moinmoin10 нояб. 2016 г.

  • CVE-2020-15275
    22Наблюдать

    malicious SVG attachment causing stored XSS vulnerability in MoinMoin

    СредняяCVSS 5,4Эксплойта нетEPSS 2 %

    moinmo · moinmoin11 нояб. 2020 г.

  • CVE-2010-1238
    21Наблюдать

    MoinMoin 1.7.1 allows remote attackers to bypass the textcha protection mechanism by modifying the textcha-question and textcha-answer field

    СредняяCVSS 5,0Эксплойта нетEPSS 2 %

    moinmo · moinmoin5 апр. 2010 г.

  • CVE-2010-0667
    21Наблюдать

    MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment

    СредняяCVSS 5,0Эксплойта нетEPSS 2 %

    moinmo · moinmoin26 февр. 2010 г.

  • CVE-2008-6549
    20Наблюдать

    The password_checker function in config/multiconfig.py in MoinMoin 1.6.1 uses the cracklib and python-crack features even though they are no

    СредняяCVSS 5,0Эксплойта нетEPSS 1 %

    moinmo · moinmoin29 мар. 2009 г.

  • CVE-2008-6548
    20Наблюдать

    The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorize

    СредняяCVSS 5,0Эксплойта нетEPSS 1 %

    moinmo · moinmoin29 мар. 2009 г.

  • CVE-2010-2487
    18Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.7.3 and earlier, 1.8.x before 1.8.8, and 1.9.x before 1.9.3 allow remote a

    СредняяCVSS 4,3Эксплойта нетEPSS 3 %

    moinmo · moinmoin5 авг. 2010 г.

  • CVE-2010-2970
    18Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.9.x before 1.9.3 allow remote attackers to inject arbitrary web script or

    СредняяCVSS 4,3Эксплойта нетEPSS 3 %

    moinmo · moinmoin5 авг. 2010 г.

  • CVE-2010-2969
    18Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.7.3 and earlier, and 1.9.x before 1.9.3, allow remote attackers to inject

    СредняяCVSS 4,3Эксплойта нетEPSS 3 %

    moinmo · moinmoin5 авг. 2010 г.

  • CVE-2009-1482
    18Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin 1.8.2 and earlier allow remote attackers to inject a

    СредняяCVSS 4,3Эксплойта нетEPSS 3 %

    moinmo · moinmoin29 апр. 2009 г.

  • CVE-2012-6082
    18Наблюдать

    Cross-site scripting (XSS) vulnerability in the rsslink function in theme/__init__.py in MoinMoin 1.9.5 allows remote attackers to inject ar

    СредняяCVSS 4,3Эксплойта нетEPSS 2 %

    moinmo · moinmoin2 янв. 2013 г.

  • CVE-2010-0828
    15Наблюдать

    Cross-site scripting (XSS) vulnerability in action/Despam.py in the Despam action module in MoinMoin 1.8.7 and 1.9.2 allows remote authentic

    НизкаяCVSS 3,5Эксплойта нетEPSS 2 %

    moinmo · moinmoin5 апр. 2010 г.