LWN.net Logo

moin: cross-site scripting

Package(s):moin CVE #(s):CVE-2010-2487
Created:August 3, 2010 Updated:August 25, 2010
Description: From the Debian advisory:

It was discovered that moin, a python clone of WikiWiki, does not sufficiently sanitize parameters when passing them to the add_msg function. This allows a remote attackers to conduct cross-site scripting (XSS) attacks for example via the template parameter.

Alerts:
Ubuntu USN-977-1 2010-08-25
Debian DSA-2083-1 2010-08-02
Gentoo 201210-02 2012-10-18

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds