CVE-2008-0782

Moinmoin - Path Traversal

Title source: rule

Description

Directory traversal vulnerability in MoinMoin 1.5.8 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the MOIN_ID user ID in a cookie for a userform action. NOTE: this issue can be leveraged for PHP code execution via the quicklinks parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by nonroot · pythonwebappsphp
https://www.exploit-db.com/exploits/4957

Scores

EPSS 0.1093
EPSS Percentile 93.4%

Details

CWE
CWE-22
Status published
Products (27)
moinmoin/moinmoin 0.1
moinmoin/moinmoin 0.2
moinmoin/moinmoin 0.3
moinmoin/moinmoin 0.7
moinmoin/moinmoin 0.8
moinmoin/moinmoin 0.9
moinmoin/moinmoin 0.10
moinmoin/moinmoin 0.11
moinmoin/moinmoin 1.0
moinmoin/moinmoin 1.1
... and 17 more
Published Feb 14, 2008
Tracked Since Feb 18, 2026