CVE-2009-0260

MoinMoin < 1.8.1 - Cross-Site Scripting via AttachFile Action Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-0260. PoCs published by SecureState.

AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in MoinMoin by injecting malicious script tags into the 'rename' and 'drawing' parameters of a URL. The vulnerability arises due to insufficient input sanitization in versions prior to MoinMoin 1.8.1.

Description

Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin before 1.8.1 allow remote attackers to inject arbitrary web script or HTML via an AttachFile action to the WikiSandBox component with (1) the rename parameter or (2) the drawing parameter (aka the basename variable).

Exploits (1)

exploitdb WORKING POC VERIFIED
by SecureState · textwebappscgi
https://www.exploit-db.com/exploits/32746

This exploit demonstrates a cross-site scripting (XSS) vulnerability in MoinMoin by injecting malicious script tags into the 'rename' and 'drawing' parameters of a URL. The vulnerability arises due to insufficient input sanitization in versions prior to MoinMoin 1.8.1.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: MoinMoin < 1.8.1
No auth needed
Prerequisites: Access to a vulnerable MoinMoin instance
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (12)

Core 12
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33593
Various Sources x_refsource_confirm
http://moinmo.in/SecurityFixes#moin1.8.1
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33755
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/0195
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33716
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/33365
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/51485
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/500197/100/0/threaded
Various Sources x_refsource_confirm
http://hg.moinmo.in/moin/1.8/rev/8cb4d34ccbc1
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/48126
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2009/dsa-1715
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/716-1/

Scores

EPSS 0.0304
EPSS Percentile 86.9%

Details

CWE
CWE-79
Status published
Products (37)
moinmoin/moinmoin 0.1
moinmoin/moinmoin 0.2
moinmoin/moinmoin 0.3
moinmoin/moinmoin 0.7
moinmoin/moinmoin 0.8
moinmoin/moinmoin 0.9
moinmoin/moinmoin 0.10
moinmoin/moinmoin 0.11
moinmoin/moinmoin 1.0
moinmoin/moinmoin 1.1
... and 27 more
Published Jan 23, 2009
Tracked Since Feb 18, 2026