Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 5.1
CVSS3: 6.1
Описание
MoinMoin Cross-site scripting (XSS) vulnerability
Cross-site scripting (XSS) vulnerability in the rsslink function in theme/__init__.py in MoinMoin before 1.9.6 allows remote attackers to inject arbitrary web script or HTML via the page name in a rss link.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2012-6082
- https://github.com/pypa/advisory-database/tree/main/vulns/moin/PYSEC-2013-23.yaml
- https://web.archive.org/web/20151023152540/http://secunia.com/advisories/51663
- https://web.archive.org/web/20200228182002/http://www.securityfocus.com/bid/57089
- http://hg.moinmo.in/moin/1.9/rev/c98ec456e493
- http://moinmo.in/SecurityFixes
- http://www.openwall.com/lists/oss-security/2012/12/29/7
- http://www.openwall.com/lists/oss-security/2012/12/30/5
Пакеты
Наименование
moin
pip
Затронутые версииВерсия исправления
< 1.9.6
1.9.6
Связанные уязвимости
ubuntu
около 13 лет назад
Cross-site scripting (XSS) vulnerability in the rsslink function in theme/__init__.py in MoinMoin 1.9.5 allows remote attackers to inject arbitrary web script or HTML via the page name in a rss link.
nvd
около 13 лет назад
Cross-site scripting (XSS) vulnerability in the rsslink function in theme/__init__.py in MoinMoin 1.9.5 allows remote attackers to inject arbitrary web script or HTML via the page name in a rss link.
debian
около 13 лет назад
Cross-site scripting (XSS) vulnerability in the rsslink function in th ...