Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-7146

Опубликовано: 10 нояб. 2016
Источник: debian
EPSS Низкий

Описание

MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation or crafted URL" approach, related to a "Cross Site Scripting (XSS)" issue affecting the action=fckdialog&dialog=attachment (via page name) component.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
moinfixed1.9.9-1package

Примечания

  • Fixed by: http://hg.moinmo.in/moin/1.9/rev/1563d6db198c

  • https://www.curesec.com/blog/article/blog/MoinMoin-198-XSS-175.html

EPSS

Процентиль: 48%
0.0025
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 9 лет назад

MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation or crafted URL" approach, related to a "Cross Site Scripting (XSS)" issue affecting the action=fckdialog&dialog=attachment (via page name) component.

CVSS3: 6.1
nvd
около 9 лет назад

MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation or crafted URL" approach, related to a "Cross Site Scripting (XSS)" issue affecting the action=fckdialog&dialog=attachment (via page name) component.

CVSS3: 6.1
github
больше 3 лет назад

MoinMoin Cross-site Scripting (XSS) vulnerability

EPSS

Процентиль: 48%
0.0025
Низкий