The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorized include files via unknown vectors.
References
Link | Resource |
---|---|
http://hg.moinmo.in/moin/1.6/rev/35ff7a9b1546 | Broken Link Vendor Advisory |
http://moinmo.in/SecurityFixes | Release Notes Vendor Advisory |
http://osvdb.org/48877 | Broken Link |
http://hg.moinmo.in/moin/1.6/rev/35ff7a9b1546 | Broken Link Vendor Advisory |
http://moinmo.in/SecurityFixes | Release Notes Vendor Advisory |
http://osvdb.org/48877 | Broken Link |
Configurations
History
21 Nov 2024, 00:56
Type | Values Removed | Values Added |
---|---|---|
References | () http://hg.moinmo.in/moin/1.6/rev/35ff7a9b1546 - Broken Link, Vendor Advisory | |
References | () http://moinmo.in/SecurityFixes - Release Notes, Vendor Advisory | |
References | () http://osvdb.org/48877 - Broken Link |
02 Feb 2024, 02:17
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-862 | |
References | (CONFIRM) http://moinmo.in/SecurityFixes - Release Notes, Vendor Advisory | |
References | (OSVDB) http://osvdb.org/48877 - Broken Link | |
References | (CONFIRM) http://hg.moinmo.in/moin/1.6/rev/35ff7a9b1546 - Broken Link, Vendor Advisory |
Information
Published : 2009-03-30 01:30
Updated : 2024-11-21 00:56
NVD link : CVE-2008-6548
Mitre link : CVE-2008-6548
CVE.ORG link : CVE-2008-6548
JSON object : View
Products Affected
moinmo
- moinmoin
CWE
CWE-862
Missing Authorization