Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin before 1.5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the page info, or the page name in a (2) AttachFile, (3) RenamePage, or (4) LocalSiteMap action.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Moinmoin | Moinmoin | * | 1.5.6 (including) |
Moinmoin | Moinmoin | 1.5.0 (including) | 1.5.0 (including) |
Moinmoin | Moinmoin | 1.5.1 (including) | 1.5.1 (including) |
Moinmoin | Moinmoin | 1.5.2 (including) | 1.5.2 (including) |
Moinmoin | Moinmoin | 1.5.3 (including) | 1.5.3 (including) |
Moinmoin | Moinmoin | 1.5.3_rc1 (including) | 1.5.3_rc1 (including) |
Moinmoin | Moinmoin | 1.5.3_rc2 (including) | 1.5.3_rc2 (including) |
Moinmoin | Moinmoin | 1.5.4 (including) | 1.5.4 (including) |
Moinmoin | Moinmoin | 1.5.5 (including) | 1.5.5 (including) |
Moinmoin | Moinmoin | 1.5.5_rc1 (including) | 1.5.5_rc1 (including) |
Moinmoin | Moinmoin | 1.5.5a (including) | 1.5.5a (including) |
Moin | Ubuntu | dapper | * |
Moin | Ubuntu | devel | * |
Moin | Ubuntu | edgy | * |
Moin | Ubuntu | feisty | * |