Search CVE reports


Toggle filters

21 – 30 of 42 results


CVE-2010-0667

Low priority
Not affected

MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable is set, which allows remote attackers to obtain sensitive information via...

1 affected package

moin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moin
Show less packages

CVE-2009-4762

Medium priority

Some fixes available 1 of 2

MoinMoin 1.7.x before 1.7.3 and 1.8.x before 1.8.3 checks parent ACLs in certain inappropriate circumstances during processing of hierarchical ACLs, which allows remote attackers to bypass intended access restrictions...

1 affected package

moin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moin
Show less packages

CVE-2009-2324

Low priority

Some fixes available 1 of 4

Multiple cross-site scripting (XSS) vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to inject arbitrary web script or HTML via components in the samples (aka _samples) directory.

2 affected packages

fckeditor, moin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fckeditor
moin
Show less packages

CVE-2009-2265

Low priority

Some fixes available 1 of 3

Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules,...

2 affected packages

moin, fckeditor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moin
fckeditor
Show less packages

CVE-2009-1482

Medium priority
Fixed

Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin 1.8.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) an AttachFile sub-action in the error_msg function or...

1 affected package

moin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moin
Show less packages

CVE-2009-0312

Low priority
Fixed

Cross-site scripting (XSS) vulnerability in the antispam feature (security/antispam.py) in MoinMoin 1.7 and 1.8.1 allows remote attackers to inject arbitrary web script or HTML via crafted, disallowed content.

1 affected package

moin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moin
Show less packages

CVE-2009-0260

Medium priority
Fixed

Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin before 1.8.1 allow remote attackers to inject arbitrary web script or HTML via an AttachFile action to the WikiSandBox component with (1) the...

1 affected package

moin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moin
Show less packages

CVE-2008-6603

Low priority
Ignored

MoinMoin 1.6.2 and 1.7 does not properly enforce ACL checks when acl_hierarchic is set to True, which might allow remote attackers to bypass intended access restrictions, a different vulnerability than CVE-2008-1937.

1 affected package

moin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moin
Show less packages

CVE-2008-6549

Medium priority
Ignored

The password_checker function in config/multiconfig.py in MoinMoin 1.6.1 uses the cracklib and python-crack features even though they are not thread-safe, which allows remote attackers to cause a denial of service (segmentation...

1 affected package

moin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moin
Show less packages

CVE-2008-6548

Low priority

Some fixes available 1 of 2

The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorized include files via unknown vectors.

1 affected package

moin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moin
Show less packages