FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2007-0857

This CVE name corresponds to:

Entered Topic
2008-02-25 moinmoin -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2007-0857
Phase Assigned(20070208)

Description

Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin before 1.5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the page info, or the page name in a (2) AttachFile, (3) RenamePage, or (4) LocalSiteMap action.

References

Source Reference
CONFIRM http://moinmoin.wikiwikiweb.de/MoinMoinRelease1.5/CHANGES
UBUNTU USN-421-1
BID 22506
VUPEN ADV-2007-0553
OSVDB 31874
OSVDB 31871
OSVDB 31872
OSVDB 31873
SECUNIA 24096
SECUNIA 24117
XF moinmoin-pageinfo-pagename-xss(32377)