CVE-2010-0668
Debian Linux Security Advisory 2014-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Unspecified vulnerability in MoinMoin 1.5.x through 1.7.x, 1.8.x before 1.8.7, and 1.9.x before 1.9.2 has unknown impact and attack vectors, related to configurations that have a non-empty superuser list, the xmlrpc action enabled, the SyncPages action enabled, or OpenID configured.
Vulnerabilidad no especificada en MoinMoin v1.5.x hasta v1.7.x, v1.8.x anteriores a v1.8.7, y v1.9.x anteriores a v1.9.2 tiene un impacto y cvector de ataque desconocido, relativo a configuraciones que tienen una lista no vacía de super-usuarios, la acción xmlrpc está disponible, la acción SyncPages está activo, o configurada OpenID.
It was discovered that several wiki actions and preference settings in MoinMoin were not protected from cross-site request forgery (CSRF). If an authenticated user were tricked into visiting a malicious website while logged into MoinMoin, a remote attacker could change the user's configuration or wiki content. It was discovered that MoinMoin did not properly sanitize its input when processing user preferences. An attacker could enter malicious content which when viewed by a user, could render in unexpected ways.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-02-21 CVE Reserved
- 2010-02-26 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (19)
URL | Tag | Source |
---|---|---|
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=569975 | X_refsource_confirm | |
http://hg.moinmo.in/moin/1.8/raw-file/1.8.7/docs/CHANGES | X_refsource_confirm | |
http://marc.info/?l=oss-security&m=126625972814888&w=2 | Mailing List | |
http://marc.info/?l=oss-security&m=126676896601156&w=2 | Mailing List | |
http://moinmo.in/MoinMoinRelease1.8 | X_refsource_confirm | |
http://secunia.com/advisories/38903 | Third Party Advisory | |
http://www.openwall.com/lists/oss-security/2010/02/15/2 | Mailing List |
|
http://www.osvdb.org/62043 | Vdb Entry | |
http://www.vupen.com/english/advisories/2010/0600 | Vdb Entry | |
https://bugzilla.redhat.com/show_bug.cgi?id=565604 | X_refsource_confirm | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/56002 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.securityfocus.com/bid/38023 | 2017-08-17 |
URL | Date | SRC |
---|---|---|
http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035374.html | 2017-08-17 | |
http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035438.html | 2017-08-17 | |
http://moinmo.in/SecurityFixes | 2017-08-17 | |
http://secunia.com/advisories/38444 | 2017-08-17 | |
http://secunia.com/advisories/38709 | 2017-08-17 | |
http://www.debian.org/security/2010/dsa-2014 | 2017-08-17 | |
http://www.vupen.com/english/advisories/2010/0266 | 2017-08-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.5.0 Search vendor "Moinmo" for product "Moinmoin" and version "1.5.0" | - |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.5.0 Search vendor "Moinmo" for product "Moinmoin" and version "1.5.0" | beta1 |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.5.0 Search vendor "Moinmo" for product "Moinmoin" and version "1.5.0" | beta2 |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.5.0 Search vendor "Moinmo" for product "Moinmoin" and version "1.5.0" | beta3 |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.5.0 Search vendor "Moinmo" for product "Moinmoin" and version "1.5.0" | beta4 |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.5.0 Search vendor "Moinmo" for product "Moinmoin" and version "1.5.0" | beta5 |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.5.0 Search vendor "Moinmo" for product "Moinmoin" and version "1.5.0" | beta6 |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.5.0 Search vendor "Moinmo" for product "Moinmoin" and version "1.5.0" | rc1 |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.5.1 Search vendor "Moinmo" for product "Moinmoin" and version "1.5.1" | - |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.5.2 Search vendor "Moinmo" for product "Moinmoin" and version "1.5.2" | - |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.5.3 Search vendor "Moinmo" for product "Moinmoin" and version "1.5.3" | - |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.5.3 Search vendor "Moinmo" for product "Moinmoin" and version "1.5.3" | rc1 |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.5.3 Search vendor "Moinmo" for product "Moinmoin" and version "1.5.3" | rc2 |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.5.4 Search vendor "Moinmo" for product "Moinmoin" and version "1.5.4" | - |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.5.5 Search vendor "Moinmo" for product "Moinmoin" and version "1.5.5" | - |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.5.5 Search vendor "Moinmo" for product "Moinmoin" and version "1.5.5" | rc1 |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.5.5a Search vendor "Moinmo" for product "Moinmoin" and version "1.5.5a" | - |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.5.6 Search vendor "Moinmo" for product "Moinmoin" and version "1.5.6" | - |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.5.7 Search vendor "Moinmo" for product "Moinmoin" and version "1.5.7" | - |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.5.8 Search vendor "Moinmo" for product "Moinmoin" and version "1.5.8" | - |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.6.0 Search vendor "Moinmo" for product "Moinmoin" and version "1.6.0" | - |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.6.0 Search vendor "Moinmo" for product "Moinmoin" and version "1.6.0" | beta1 |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.6.0 Search vendor "Moinmo" for product "Moinmoin" and version "1.6.0" | beta2 |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.6.0 Search vendor "Moinmo" for product "Moinmoin" and version "1.6.0" | rc1 |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.6.0 Search vendor "Moinmo" for product "Moinmoin" and version "1.6.0" | rc2 |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.6.1 Search vendor "Moinmo" for product "Moinmoin" and version "1.6.1" | - |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.6.2 Search vendor "Moinmo" for product "Moinmoin" and version "1.6.2" | - |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.6.3 Search vendor "Moinmo" for product "Moinmoin" and version "1.6.3" | - |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.6.4 Search vendor "Moinmo" for product "Moinmoin" and version "1.6.4" | - |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.7.0 Search vendor "Moinmo" for product "Moinmoin" and version "1.7.0" | - |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.7.0 Search vendor "Moinmo" for product "Moinmoin" and version "1.7.0" | beta1 |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.7.0 Search vendor "Moinmo" for product "Moinmoin" and version "1.7.0" | beta2 |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.7.0 Search vendor "Moinmo" for product "Moinmoin" and version "1.7.0" | rc1 |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.7.0 Search vendor "Moinmo" for product "Moinmoin" and version "1.7.0" | rc2 |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.7.0 Search vendor "Moinmo" for product "Moinmoin" and version "1.7.0" | rc3 |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.7.1 Search vendor "Moinmo" for product "Moinmoin" and version "1.7.1" | - |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.7.2 Search vendor "Moinmo" for product "Moinmoin" and version "1.7.2" | - |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.7.3 Search vendor "Moinmo" for product "Moinmoin" and version "1.7.3" | - |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.8.0 Search vendor "Moinmo" for product "Moinmoin" and version "1.8.0" | - |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.8.1 Search vendor "Moinmo" for product "Moinmoin" and version "1.8.1" | - |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.8.2 Search vendor "Moinmo" for product "Moinmoin" and version "1.8.2" | - |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.8.3 Search vendor "Moinmo" for product "Moinmoin" and version "1.8.3" | - |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.8.4 Search vendor "Moinmo" for product "Moinmoin" and version "1.8.4" | - |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.8.6 Search vendor "Moinmo" for product "Moinmoin" and version "1.8.6" | - |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.9.0 Search vendor "Moinmo" for product "Moinmoin" and version "1.9.0" | - |
Affected
| ||||||
Moinmo Search vendor "Moinmo" | Moinmoin Search vendor "Moinmo" for product "Moinmoin" | 1.9.1 Search vendor "Moinmo" for product "Moinmoin" and version "1.9.1" | - |
Affected
|