moinmo kayıtları
moinmo üreticisine ait 26 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %3,8
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-264 Permissions, Privileges, and Access Controls4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-16 Configuration1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-862 Missing Authorization1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
26 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2020-25074İstismar yok | The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request.moinmo · moinmoin · CWE-22 | Kritik9,8 | — | %6,6 | 10 Kas 2020 |
35İzleyin | CVE-2012-6081Silahlaştırılmış | Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actmoinmo · moinmoin | Orta6,0 | — | %35,3 | 2 Oca 2013 |
31İzleyin | CVE-2009-4762İstismar yok | MoinMoin 1.7.x before 1.7.3 and 1.8.x before 1.8.3 checks parent ACLs in certain inappropriate circumstances during processing of hierarchicmoinmo · moinmoin · CWE-264 | Yüksek7,5 | — | %3,1 | 29 Mar 2010 |
31İzleyin | CVE-2010-0717İstismar yok | The default configuration of cfg.packagepages_actions_excluded in MoinMoin before 1.8.7 does not prevent unsafe package actions, which has umoinmo · moinmoin · CWE-16 | Yüksek7,5 | — | %2,0 | 26 Şub 2010 |
31İzleyin | CVE-2010-0669İstismar yok | MoinMoin before 1.8.7 and 1.9.x before 1.9.2 does not properly sanitize user profiles, which has unspecified impact and attack vectors.moinmo · moinmoin | Yüksek7,5 | — | %1,9 | 26 Şub 2010 |
30İzleyin | CVE-2012-6495Kavram kanıtı | Multiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions moinmo · moinmoin · CWE-22 | Orta6,0 | — | %18,7 | 2 Oca 2013 |
28İzleyin | CVE-2010-0668İstismar yok | Unspecified vulnerability in MoinMoin 1.5.x through 1.7.x, 1.8.x before 1.8.7, and 1.9.x before 1.9.2 has unknown impact and attack vectors,moinmo · moinmoin | Orta6,8 | — | %2,2 | 26 Şub 2010 |
27İzleyin | CVE-2008-6603İstismar yok | MoinMoin 1.6.2 and 1.7 does not properly enforce ACL checks when acl_hierarchic is set to True, which might allow remote attackers to bypassmoinmo · moinmoin · CWE-264 | Orta6,8 | — | %1,7 | 3 Nis 2009 |
26İzleyin | CVE-2012-6080İstismar yok | Directory traversal vulnerability in the _do_attachment_move function in the AttachFile action (action/AttachFile.py) in MoinMoin 1.9.3 thromoinmo · moinmoin · CWE-22 | Orta6,4 | — | %4,1 | 2 Oca 2013 |
25İzleyin | CVE-2012-4404İstismar yok | security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Knomoinmo · moinmoin · CWE-264 | Orta6,0 | — | %2,1 | 10 Eyl 2012 |
25İzleyin | CVE-2017-5934İstismar yok | Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbimoinmo · moinmoin · CWE-79 | Orta6,1 | — | %1,9 | 15 Eki 2018 |
24İzleyin | CVE-2016-9119İstismar yok | Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.8 allows remote attackers to inject arbitmoinmo · moinmoin · CWE-79 | Orta6,1 | — | %1,5 | 30 Oca 2017 |
24İzleyin | CVE-2016-7146İstismar yok | MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation or crafted URL" approach, relatmoinmo · moinmoin · CWE-79 | Orta6,1 | — | %1,2 | 10 Kas 2016 |
24İzleyin | CVE-2016-7148İstismar yok | MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation" approach, related to a "Cross moinmo · moinmoin · CWE-79 | Orta6,1 | — | %1,2 | 10 Kas 2016 |
22İzleyin | CVE-2020-15275İstismar yok | malicious SVG attachment causing stored XSS vulnerability in MoinMoinmoinmo · moinmoin · CWE-79 | Orta5,4 | — | %1,7 | 11 Kas 2020 |
21İzleyin | CVE-2010-1238İstismar yok | MoinMoin 1.7.1 allows remote attackers to bypass the textcha protection mechanism by modifying the textcha-question and textcha-answer fieldmoinmo · moinmoin · CWE-264 | Orta5,0 | — | %2,0 | 5 Nis 2010 |
21İzleyin | CVE-2010-0667İstismar yok | MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environmentmoinmo · moinmoin · CWE-200 | Orta5,0 | — | %1,9 | 26 Şub 2010 |
20İzleyin | CVE-2008-6549İstismar yok | The password_checker function in config/multiconfig.py in MoinMoin 1.6.1 uses the cracklib and python-crack features even though they are nomoinmo · moinmoin | Orta5,0 | — | %1,5 | 29 Mar 2009 |
20İzleyin | CVE-2008-6548İstismar yok | The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorizemoinmo · moinmoin · CWE-862 | Orta5,0 | — | %1,0 | 29 Mar 2009 |
18İzleyin | CVE-2010-2487İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.7.3 and earlier, 1.8.x before 1.8.8, and 1.9.x before 1.9.3 allow remote amoinmo · moinmoin · CWE-79 | Orta4,3 | — | %2,7 | 5 Ağu 2010 |
18İzleyin | CVE-2010-2970İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.9.x before 1.9.3 allow remote attackers to inject arbitrary web script or moinmo · moinmoin · CWE-79 | Orta4,3 | — | %2,6 | 5 Ağu 2010 |
18İzleyin | CVE-2010-2969İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.7.3 and earlier, and 1.9.x before 1.9.3, allow remote attackers to inject moinmo · moinmoin · CWE-79 | Orta4,3 | — | %2,6 | 5 Ağu 2010 |
18İzleyin | CVE-2009-1482İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin 1.8.2 and earlier allow remote attackers to inject amoinmo · moinmoin · CWE-79 | Orta4,3 | — | %2,5 | 29 Nis 2009 |
18İzleyin | CVE-2012-6082İstismar yok | Cross-site scripting (XSS) vulnerability in the rsslink function in theme/__init__.py in MoinMoin 1.9.5 allows remote attackers to inject armoinmo · moinmoin · CWE-79 | Orta4,3 | — | %2,1 | 2 Oca 2013 |
15İzleyin | CVE-2010-0828İstismar yok | Cross-site scripting (XSS) vulnerability in action/Despam.py in the Despam action module in MoinMoin 1.8.7 and 1.9.2 allows remote authenticmoinmo · moinmoin · CWE-79 | Düşük3,5 | — | %2,3 | 5 Nis 2010 |
- CVE-2020-2507441Planlayın
The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request.
KritikCVSS 9,8İstismar yokEPSS %7moinmo · moinmoin10 Kas 2020
- CVE-2012-608135İzleyin
Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) act
OrtaCVSS 6,0SilahlaştırılmışEPSS %35moinmo · moinmoin2 Oca 2013
- CVE-2009-476231İzleyin
MoinMoin 1.7.x before 1.7.3 and 1.8.x before 1.8.3 checks parent ACLs in certain inappropriate circumstances during processing of hierarchic
YüksekCVSS 7,5İstismar yokEPSS %3moinmo · moinmoin29 Mar 2010
- CVE-2010-071731İzleyin
The default configuration of cfg.packagepages_actions_excluded in MoinMoin before 1.8.7 does not prevent unsafe package actions, which has u
YüksekCVSS 7,5İstismar yokEPSS %2moinmo · moinmoin26 Şub 2010
- CVE-2010-066931İzleyin
MoinMoin before 1.8.7 and 1.9.x before 1.9.2 does not properly sanitize user profiles, which has unspecified impact and attack vectors.
YüksekCVSS 7,5İstismar yokEPSS %2moinmo · moinmoin26 Şub 2010
- CVE-2012-649530İzleyin
Multiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions
OrtaCVSS 6,0Kavram kanıtıEPSS %19moinmo · moinmoin2 Oca 2013
- CVE-2010-066828İzleyin
Unspecified vulnerability in MoinMoin 1.5.x through 1.7.x, 1.8.x before 1.8.7, and 1.9.x before 1.9.2 has unknown impact and attack vectors,
OrtaCVSS 6,8İstismar yokEPSS %2moinmo · moinmoin26 Şub 2010
- CVE-2008-660327İzleyin
MoinMoin 1.6.2 and 1.7 does not properly enforce ACL checks when acl_hierarchic is set to True, which might allow remote attackers to bypass
OrtaCVSS 6,8İstismar yokEPSS %2moinmo · moinmoin3 Nis 2009
- CVE-2012-608026İzleyin
Directory traversal vulnerability in the _do_attachment_move function in the AttachFile action (action/AttachFile.py) in MoinMoin 1.9.3 thro
OrtaCVSS 6,4İstismar yokEPSS %4moinmo · moinmoin2 Oca 2013
- CVE-2012-440425İzleyin
security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Kno
OrtaCVSS 6,0İstismar yokEPSS %2moinmo · moinmoin10 Eyl 2012
- CVE-2017-593425İzleyin
Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbi
OrtaCVSS 6,1İstismar yokEPSS %2moinmo · moinmoin15 Eki 2018
- CVE-2016-911924İzleyin
Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.8 allows remote attackers to inject arbit
OrtaCVSS 6,1İstismar yokEPSS %1moinmo · moinmoin30 Oca 2017
- CVE-2016-714624İzleyin
MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation or crafted URL" approach, relat
OrtaCVSS 6,1İstismar yokEPSS %1moinmo · moinmoin10 Kas 2016
- CVE-2016-714824İzleyin
MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation" approach, related to a "Cross
OrtaCVSS 6,1İstismar yokEPSS %1moinmo · moinmoin10 Kas 2016
- CVE-2020-1527522İzleyin
malicious SVG attachment causing stored XSS vulnerability in MoinMoin
OrtaCVSS 5,4İstismar yokEPSS %2moinmo · moinmoin11 Kas 2020
- CVE-2010-123821İzleyin
MoinMoin 1.7.1 allows remote attackers to bypass the textcha protection mechanism by modifying the textcha-question and textcha-answer field
OrtaCVSS 5,0İstismar yokEPSS %2moinmo · moinmoin5 Nis 2010
- CVE-2010-066721İzleyin
MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment
OrtaCVSS 5,0İstismar yokEPSS %2moinmo · moinmoin26 Şub 2010
- CVE-2008-654920İzleyin
The password_checker function in config/multiconfig.py in MoinMoin 1.6.1 uses the cracklib and python-crack features even though they are no
OrtaCVSS 5,0İstismar yokEPSS %1moinmo · moinmoin29 Mar 2009
- CVE-2008-654820İzleyin
The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorize
OrtaCVSS 5,0İstismar yokEPSS %1moinmo · moinmoin29 Mar 2009
- CVE-2010-248718İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.7.3 and earlier, 1.8.x before 1.8.8, and 1.9.x before 1.9.3 allow remote a
OrtaCVSS 4,3İstismar yokEPSS %3moinmo · moinmoin5 Ağu 2010
- CVE-2010-297018İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.9.x before 1.9.3 allow remote attackers to inject arbitrary web script or
OrtaCVSS 4,3İstismar yokEPSS %3moinmo · moinmoin5 Ağu 2010
- CVE-2010-296918İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.7.3 and earlier, and 1.9.x before 1.9.3, allow remote attackers to inject
OrtaCVSS 4,3İstismar yokEPSS %3moinmo · moinmoin5 Ağu 2010
- CVE-2009-148218İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin 1.8.2 and earlier allow remote attackers to inject a
OrtaCVSS 4,3İstismar yokEPSS %3moinmo · moinmoin29 Nis 2009
- CVE-2012-608218İzleyin
Cross-site scripting (XSS) vulnerability in the rsslink function in theme/__init__.py in MoinMoin 1.9.5 allows remote attackers to inject ar
OrtaCVSS 4,3İstismar yokEPSS %2moinmo · moinmoin2 Oca 2013
- CVE-2010-082815İzleyin
Cross-site scripting (XSS) vulnerability in action/Despam.py in the Despam action module in MoinMoin 1.8.7 and 1.9.2 allows remote authentic
DüşükCVSS 3,5İstismar yokEPSS %2moinmo · moinmoin5 Nis 2010