Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote authenticated users with write permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory, as exploited in the wild in July 2012.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Moinmoin | Moinmo | * | 1.9.5 (including) |
Moinmoin | Moinmo | 0.1 (including) | 0.1 (including) |
Moinmoin | Moinmo | 0.2 (including) | 0.2 (including) |
Moinmoin | Moinmo | 0.3 (including) | 0.3 (including) |
Moinmoin | Moinmo | 0.4 (including) | 0.4 (including) |
Moinmoin | Moinmo | 0.5 (including) | 0.5 (including) |
Moinmoin | Moinmo | 0.6 (including) | 0.6 (including) |
Moinmoin | Moinmo | 0.7 (including) | 0.7 (including) |
Moinmoin | Moinmo | 0.8 (including) | 0.8 (including) |
Moinmoin | Moinmo | 0.9 (including) | 0.9 (including) |
Moinmoin | Moinmo | 0.10 (including) | 0.10 (including) |
Moinmoin | Moinmo | 0.11 (including) | 0.11 (including) |
Moinmoin | Moinmo | 1.0 (including) | 1.0 (including) |
Moinmoin | Moinmo | 1.1 (including) | 1.1 (including) |
Moinmoin | Moinmo | 1.2 (including) | 1.2 (including) |
Moinmoin | Moinmo | 1.2.1 (including) | 1.2.1 (including) |
Moinmoin | Moinmo | 1.2.2 (including) | 1.2.2 (including) |
Moinmoin | Moinmo | 1.2.3 (including) | 1.2.3 (including) |
Moinmoin | Moinmo | 1.2.4 (including) | 1.2.4 (including) |
Moinmoin | Moinmo | 1.3.0 (including) | 1.3.0 (including) |
Moinmoin | Moinmo | 1.3.1 (including) | 1.3.1 (including) |
Moinmoin | Moinmo | 1.3.2 (including) | 1.3.2 (including) |
Moinmoin | Moinmo | 1.3.3 (including) | 1.3.3 (including) |
Moinmoin | Moinmo | 1.3.4 (including) | 1.3.4 (including) |
Moinmoin | Moinmo | 1.3.5 (including) | 1.3.5 (including) |
Moinmoin | Moinmo | 1.3.5-rc1 (including) | 1.3.5-rc1 (including) |
Moinmoin | Moinmo | 1.4 (including) | 1.4 (including) |
Moinmoin | Moinmo | 1.5.0 (including) | 1.5.0 (including) |
Moinmoin | Moinmo | 1.5.0-beta1 (including) | 1.5.0-beta1 (including) |
Moinmoin | Moinmo | 1.5.0-beta2 (including) | 1.5.0-beta2 (including) |
Moinmoin | Moinmo | 1.5.0-beta3 (including) | 1.5.0-beta3 (including) |
Moinmoin | Moinmo | 1.5.0-beta4 (including) | 1.5.0-beta4 (including) |
Moinmoin | Moinmo | 1.5.0-beta5 (including) | 1.5.0-beta5 (including) |
Moinmoin | Moinmo | 1.5.0-beta6 (including) | 1.5.0-beta6 (including) |
Moinmoin | Moinmo | 1.5.0-rc1 (including) | 1.5.0-rc1 (including) |
Moinmoin | Moinmo | 1.5.1 (including) | 1.5.1 (including) |
Moinmoin | Moinmo | 1.5.2 (including) | 1.5.2 (including) |
Moinmoin | Moinmo | 1.5.3 (including) | 1.5.3 (including) |
Moinmoin | Moinmo | 1.5.3-rc1 (including) | 1.5.3-rc1 (including) |
Moinmoin | Moinmo | 1.5.3-rc2 (including) | 1.5.3-rc2 (including) |
Moinmoin | Moinmo | 1.5.4 (including) | 1.5.4 (including) |
Moinmoin | Moinmo | 1.5.5 (including) | 1.5.5 (including) |
Moinmoin | Moinmo | 1.5.5-a (including) | 1.5.5-a (including) |
Moinmoin | Moinmo | 1.5.5-rc1 (including) | 1.5.5-rc1 (including) |
Moinmoin | Moinmo | 1.5.5a (including) | 1.5.5a (including) |
Moinmoin | Moinmo | 1.5.6 (including) | 1.5.6 (including) |
Moinmoin | Moinmo | 1.5.7 (including) | 1.5.7 (including) |
Moinmoin | Moinmo | 1.5.8 (including) | 1.5.8 (including) |
Moinmoin | Moinmo | 1.6.0 (including) | 1.6.0 (including) |
Moinmoin | Moinmo | 1.6.0-beta1 (including) | 1.6.0-beta1 (including) |
Moinmoin | Moinmo | 1.6.0-beta2 (including) | 1.6.0-beta2 (including) |
Moinmoin | Moinmo | 1.6.0-rc1 (including) | 1.6.0-rc1 (including) |
Moinmoin | Moinmo | 1.6.0-rc2 (including) | 1.6.0-rc2 (including) |
Moinmoin | Moinmo | 1.6.1 (including) | 1.6.1 (including) |
Moinmoin | Moinmo | 1.6.2 (including) | 1.6.2 (including) |
Moinmoin | Moinmo | 1.6.3 (including) | 1.6.3 (including) |
Moinmoin | Moinmo | 1.6.4 (including) | 1.6.4 (including) |
Moinmoin | Moinmo | 1.7.0 (including) | 1.7.0 (including) |
Moinmoin | Moinmo | 1.7.0-beta1 (including) | 1.7.0-beta1 (including) |
Moinmoin | Moinmo | 1.7.0-beta2 (including) | 1.7.0-beta2 (including) |
Moinmoin | Moinmo | 1.7.0-rc1 (including) | 1.7.0-rc1 (including) |
Moinmoin | Moinmo | 1.7.0-rc2 (including) | 1.7.0-rc2 (including) |
Moinmoin | Moinmo | 1.7.0-rc3 (including) | 1.7.0-rc3 (including) |
Moinmoin | Moinmo | 1.7.1 (including) | 1.7.1 (including) |
Moinmoin | Moinmo | 1.7.2 (including) | 1.7.2 (including) |
Moinmoin | Moinmo | 1.7.3 (including) | 1.7.3 (including) |
Moinmoin | Moinmo | 1.8.0 (including) | 1.8.0 (including) |
Moinmoin | Moinmo | 1.8.1 (including) | 1.8.1 (including) |
Moinmoin | Moinmo | 1.8.2 (including) | 1.8.2 (including) |
Moinmoin | Moinmo | 1.8.3 (including) | 1.8.3 (including) |
Moinmoin | Moinmo | 1.8.4 (including) | 1.8.4 (including) |
Moinmoin | Moinmo | 1.8.6 (including) | 1.8.6 (including) |
Moinmoin | Moinmo | 1.8.7 (including) | 1.8.7 (including) |
Moinmoin | Moinmo | 1.8.8 (including) | 1.8.8 (including) |
Moinmoin | Moinmo | 1.9.0 (including) | 1.9.0 (including) |
Moinmoin | Moinmo | 1.9.1 (including) | 1.9.1 (including) |
Moinmoin | Moinmo | 1.9.2 (including) | 1.9.2 (including) |
Moinmoin | Moinmo | 1.9.3 (including) | 1.9.3 (including) |
Moinmoin | Moinmo | 1.9.4 (including) | 1.9.4 (including) |
Moin | Ubuntu | devel | * |
Moin | Ubuntu | hardy | * |
Moin | Ubuntu | lucid | * |
Moin | Ubuntu | oneiric | * |
Moin | Ubuntu | precise | * |
Moin | Ubuntu | quantal | * |
Moin | Ubuntu | upstream | * |