MoinMoin Multiple Cross Site Scripting Vulnerabilities
BID:27904
Info
MoinMoin Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 27904 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0781 CVE-2008-0780 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 20 2008 12:00AM |
| Updated: | Apr 13 2015 08:36PM |
| Credit: | Fernando Quintero is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.10 sparc Ubuntu Ubuntu Linux 8.10 powerpc Ubuntu Ubuntu Linux 8.10 lpia Ubuntu Ubuntu Linux 8.10 i386 Ubuntu Ubuntu Linux 8.10 amd64 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 lpia Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 MoinMoin MoinMoin 1.6 MoinMoin MoinMoin 1.5.8 MoinMoin MoinMoin 1.5.7 MoinMoin MoinMoin 1.5.6 MoinMoin MoinMoin 1.5.5 MoinMoin MoinMoin 1.5.4 MoinMoin MoinMoin 1.5.3 MoinMoin MoinMoin 1.5.2 MoinMoin MoinMoin 1.5 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
MoinMoin MoinMoin 1.6.1 |
Discussion
MoinMoin Multiple Cross Site Scripting Vulnerabilities
MoinMoin is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials and to launch other attacks.
These issues affect the following versions:
MoinMoin 1.5.8 and prior versions
MoinMoin 1.6.x prior to 1.6.1.
MoinMoin is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials and to launch other attacks.
These issues affect the following versions:
MoinMoin 1.5.8 and prior versions
MoinMoin 1.6.x prior to 1.6.1.
Exploit / POC
MoinMoin Multiple Cross Site Scripting Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
MoinMoin Multiple Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
MoinMoin MoinMoin 1.5
MoinMoin MoinMoin 1.5.2
MoinMoin MoinMoin 1.5.3
MoinMoin MoinMoin 1.5.4
MoinMoin MoinMoin 1.5.5
MoinMoin MoinMoin 1.5.6
MoinMoin MoinMoin 1.5.7
MoinMoin MoinMoin 1.5.8
MoinMoin MoinMoin 1.6
Solution:
Updates are available. Please see the references for more information.
MoinMoin MoinMoin 1.5
-
MoinMoin moin-1.6.1.tar.gz
http://static.moinmo.in/files/moin-1.6.1.tar.gz
MoinMoin MoinMoin 1.5.2
-
MoinMoin moin-1.6.1.tar.gz
http://static.moinmo.in/files/moin-1.6.1.tar.gz
MoinMoin MoinMoin 1.5.3
-
MoinMoin moin-1.6.1.tar.gz
http://static.moinmo.in/files/moin-1.6.1.tar.gz
MoinMoin MoinMoin 1.5.4
-
MoinMoin moin-1.6.1.tar.gz
http://static.moinmo.in/files/moin-1.6.1.tar.gz
MoinMoin MoinMoin 1.5.5
-
MoinMoin moin-1.6.1.tar.gz
http://static.moinmo.in/files/moin-1.6.1.tar.gz
MoinMoin MoinMoin 1.5.6
-
MoinMoin moin-1.6.1.tar.gz
http://static.moinmo.in/files/moin-1.6.1.tar.gz
MoinMoin MoinMoin 1.5.7
-
MoinMoin moin-1.6.1.tar.gz
http://static.moinmo.in/files/moin-1.6.1.tar.gz
MoinMoin MoinMoin 1.5.8
-
MoinMoin moin-1.6.1.tar.gz
http://static.moinmo.in/files/moin-1.6.1.tar.gz
MoinMoin MoinMoin 1.6
-
MoinMoin moin-1.6.1.tar.gz
http://static.moinmo.in/files/moin-1.6.1.tar.gz
References
MoinMoin Multiple Cross Site Scripting Vulnerabilities
References:
References: