Описание
Cross-site scripting (XSS) vulnerability in the rsslink function in theme/__init__.py in MoinMoin 1.9.5 allows remote attackers to inject arbitrary web script or HTML via the page name in a rss link.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| moin | fixed | 1.9.5-2 | package | |
| moin | fixed | 1.9.4-8+deb7u1 | wheezy | package |
Примечания
Fix http://hg.moinmo.in/moin/1.9/rev/c98ec456e493
Связанные уязвимости
ubuntu
около 13 лет назад
Cross-site scripting (XSS) vulnerability in the rsslink function in theme/__init__.py in MoinMoin 1.9.5 allows remote attackers to inject arbitrary web script or HTML via the page name in a rss link.
nvd
около 13 лет назад
Cross-site scripting (XSS) vulnerability in the rsslink function in theme/__init__.py in MoinMoin 1.9.5 allows remote attackers to inject arbitrary web script or HTML via the page name in a rss link.
CVSS3: 6.1
github
больше 3 лет назад
MoinMoin Cross-site scripting (XSS) vulnerability