Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 256621 (CVE-2009-0312)

Summary: <=www-apps/moinmoin-{1.7.3,1.8.1} antispam XSS (CVE-2009-0312)
Product: Gentoo Security Reporter: Robert Buchholz (RETIRED) <rbu>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor CC: web-apps
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://moinmo.in/SecurityFixes#moin1.8.1
Whiteboard: B4 [noglsa]
Package list:
Runtime testing required: ---
Bug Depends on: 268565    
Bug Blocks:    

Description Robert Buchholz (RETIRED) gentoo-dev 2009-01-28 12:36:20 UTC
CVE-2009-0312 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0312):
  Cross-site scripting (XSS) vulnerability in the antispam feature
  (security/antispam.py) in MoinMoin 1.7 and 1.8.1 allows remote
  attackers to inject arbitrary web script or HTML via crafted,
  disallowed content.