Описание
The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorized include files via unknown vectors.
Ссылки
- Broken LinkVendor Advisory
- Release NotesVendor Advisory
- Broken Link
- Broken LinkVendor Advisory
- Release NotesVendor Advisory
- Broken Link
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:moinmo:moinmoin:1.6.1:*:*:*:*:*:*:*
EPSS
Процентиль: 46%
0.00228
Низкий
5 Medium
CVSS2
Дефекты
CWE-862
Связанные уязвимости
ubuntu
больше 16 лет назад
The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorized include files via unknown vectors.
debian
больше 16 лет назад
The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check t ...
CVSS3: 5.3
github
больше 3 лет назад
MoinMoin improper access control on the included page for the rst parser
EPSS
Процентиль: 46%
0.00228
Низкий
5 Medium
CVSS2
Дефекты
CWE-862