MEDIUM
MoinMoin multiple XSS in AttachFile action
Published Feb 14, 2008
4.3
MEDIUMCVSS 2.0
EPSS 2.56%
Description
Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin 1.5.8 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) message, (2) pagename, and (3) target filenames.
Affected products
No data.
OR
- 0.1
- 0.2
- 0.3
- 0.7
- 0.8
- 0.9
- 0.10
- 0.11
- 1.0
- 1.1
- 1.2
- 1.2.1
- 1.2.2
- 1.5.0
- 1.5.1
- 1.5.2
- 1.5.3
- 1.5.3_rc1
- 1.5.3_rc2
- 1.5.4
- 1.5.5
- 1.5.5_rc1
- 1.5.5a
- 1.5.6
- 1.5.7
- 1.5.8
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (19)
- http://hg.moinmo.in/moin/1.5/rev/db212dfc58ef x_refsource_CONFIRM
- http://secunia.com/advisories/28987 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29010 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29262 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29444 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/33755 third-party-advisoryx_refsource_SECUNIA
- http://www.debian.org/security/2008/dsa-1514 vendor-advisoryx_refsource_DEBIAN
- http://www.gentoo.org/security/en/glsa/glsa-200803-27.xml vendor-advisoryx_refsource_GENTOO
- http://www.securityfocus.com/bid/27904 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2008/0569/references vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2008-0781 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=432748 x_refsource_CONFIRMIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-2936 Advisory
- https://github.com/advisories/GHSA-775g-4482-pm94 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2008-0781
- https://usn.ubuntu.com/716-1 vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2008-0781
- https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00726.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00752.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 14, 2008
Updated Aug 7, 2024
Reserved Feb 14, 2008
Link CVE-2008-0781
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-2936 GHSA-775G-4482-PM94 Assigner mitre
Published Feb 14, 2008
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2022-2936