MoinMoin MOIN_ID Cookie Remote Input Validation Vulnerability
BID:27404
Info
MoinMoin MOIN_ID Cookie Remote Input Validation Vulnerability
| Bugtraq ID: | 27404 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0782 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 22 2008 12:00AM |
| Updated: | Jan 30 2009 06:49PM |
| Credit: | This issue was discovered by just a nonroot and colombian user. |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.10 sparc Ubuntu Ubuntu Linux 8.10 powerpc Ubuntu Ubuntu Linux 8.10 lpia Ubuntu Ubuntu Linux 8.10 i386 Ubuntu Ubuntu Linux 8.10 amd64 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 lpia Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 MoinMoin MoinMoin 1.5.8 MoinMoin MoinMoin 1.5.7 MoinMoin MoinMoin 1.5.6 MoinMoin MoinMoin 1.5.5 MoinMoin MoinMoin 1.5.4 MoinMoin MoinMoin 1.5.3 MoinMoin MoinMoin 1.5.2 MoinMoin MoinMoin 1.5 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: | |
Discussion
MoinMoin MOIN_ID Cookie Remote Input Validation Vulnerability
MoinMoin is prone to an input-validation vulnerability because it fails to properly sanitize user-supplied cookie data.
An attacker can exploit this issue to gain unauthorized access to the affected application, which may lead to further attacks.
Versions in the MoinMoin 1.5 series are vulnerable.
UPDATE: The 'quicklinks' parameter may be used to insert PHP code into writable files in conjunction with this issue. Attackers could potentially inject executable script code into writable PHP files located outside of the MoinMoin installation.
MoinMoin is prone to an input-validation vulnerability because it fails to properly sanitize user-supplied cookie data.
An attacker can exploit this issue to gain unauthorized access to the affected application, which may lead to further attacks.
Versions in the MoinMoin 1.5 series are vulnerable.
UPDATE: The 'quicklinks' parameter may be used to insert PHP code into writable files in conjunction with this issue. Attackers could potentially inject executable script code into writable PHP files located outside of the MoinMoin installation.
Exploit / POC
MoinMoin MOIN_ID Cookie Remote Input Validation Vulnerability
An attacker can use a browser to exploit this issue.
The following exploit is available:
An attacker can use a browser to exploit this issue.
The following exploit is available:
Solution / Fix
MoinMoin MOIN_ID Cookie Remote Input Validation Vulnerability
Solution:
The vendor has committed a fix to the MoinMoin mercurial repository. Users of affected packages should contact the vendor for details on obtaining fixes.
Solution:
The vendor has committed a fix to the MoinMoin mercurial repository. Users of affected packages should contact the vendor for details on obtaining fixes.
References
MoinMoin MOIN_ID Cookie Remote Input Validation Vulnerability
References:
References:
- [VIM] MoinMoin 1.5.x MOIND_ID cookie Bug Remote Exploit (George A. Theall)
- MoinMoin Homepage (MoinMoin)
- Security fix: only accept valid user IDs from the cookie (MoinMoin)