Описание
The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorized include files via unknown vectors.
| Релиз | Статус | Примечание |
|---|---|---|
| dapper | released | 1.5.2-1ubuntu2.3 |
| devel | not-affected | 1.8.2-2ubuntu2 |
| gutsy | ignored | end of life, was needed |
| hardy | not-affected | 1.5.8-5.1ubuntu2.2 |
| intrepid | not-affected | 1.7.1-1ubuntu1.1 |
| jaunty | not-affected | 1.8.2-2ubuntu2 |
| karmic | not-affected | 1.8.2-2ubuntu2 |
| upstream | released | 1.6.2 and 1.5.8 |
Показывать по
10
EPSS
Процентиль: 45%
0.00228
Низкий
5 Medium
CVSS2
Связанные уязвимости
nvd
больше 16 лет назад
The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorized include files via unknown vectors.
debian
больше 16 лет назад
The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check t ...
CVSS3: 5.3
github
больше 3 лет назад
MoinMoin improper access control on the included page for the rst parser
EPSS
Процентиль: 45%
0.00228
Низкий
5 Medium
CVSS2