Description
Unspecified vulnerability in MoinMoin 1.5.x through 1.7.x, 1.8.x before 1.8.7, and 1.9.x before 1.9.2 has unknown impact and attack vectors, related to configurations that have a non-empty superuser list, the xmlrpc action enabled, the SyncPages action enabled, or OpenID configured.
References (19)
Core 19
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/56002
Patch vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/38023
Vendor Advisory x_refsource_confirm
http://moinmo.in/SecurityFixes
Various Sources x_refsource_confirm
http://hg.moinmo.in/moin/1.8/raw-file/1.8.7/docs/CHANGES
Issue Tracking x_refsource_confirm
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=569975
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=565604
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/62043
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2010/02/15/2
Mailing List mailing-list
x_refsource_mlist
http://marc.info/?l=oss-security&m=126676896601156&w=2
Various Sources x_refsource_confirm
http://moinmo.in/MoinMoinRelease1.8
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/38709
Mailing List mailing-list
x_refsource_mlist
http://marc.info/?l=oss-security&m=126625972814888&w=2
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2010/dsa-2014
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035438.html
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/38444
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/38903
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035374.html
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0600
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0266
Scores
EPSS
0.0218
EPSS Percentile
80.5%
Details
Status
published
Products (28)
moinmo/moinmoin
1.5.0 (8 CPE variants)
moinmo/moinmoin
1.5.1
moinmo/moinmoin
1.5.2
moinmo/moinmoin
1.5.3 (3 CPE variants)
moinmo/moinmoin
1.5.4
moinmo/moinmoin
1.5.5 (2 CPE variants)
moinmo/moinmoin
1.5.5a
moinmo/moinmoin
1.5.6
moinmo/moinmoin
1.5.7
moinmo/moinmoin
1.5.8
... and 18 more
Published
Feb 26, 2010
Tracked Since
Feb 18, 2026