LWN.net Logo

MoinMoin: cross-site scripting and information leak

Package(s):moin moinmoin CVE #(s):CVE-2007-0901 CVE-2007-0902
Created:February 21, 2007 Updated:February 21, 2007
Description: MoinMoin suffers from a pair of vulnerabilities. An attacker who tricks a MoinMoin user into viewing a specially-crafted URL can execute arbitrary JavaScript with the user's privileges. There is also an information disclosure vulnerability which can tell an attacker about the versions of software running on the system.
Alerts:
Ubuntu USN-423-1 2007-02-20

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds