Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 256621 (CVE-2009-0312) - <=www-apps/moinmoin-{1.7.3,1.8.1} antispam XSS (CVE-2009-0312)
Summary: <=www-apps/moinmoin-{1.7.3,1.8.1} antispam XSS (CVE-2009-0312)
Status: RESOLVED FIXED
Alias: CVE-2009-0312
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://moinmo.in/SecurityFixes#moin1.8.1
Whiteboard: B4 [noglsa]
Keywords:
Depends on: 268565
Blocks:
  Show dependency tree
 
Reported: 2009-01-28 12:36 UTC by Robert Buchholz (RETIRED)
Modified: 2009-06-21 18:15 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2009-01-28 12:36:20 UTC
CVE-2009-0312 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0312):
  Cross-site scripting (XSS) vulnerability in the antispam feature
  (security/antispam.py) in MoinMoin 1.7 and 1.8.1 allows remote
  attackers to inject arbitrary web script or HTML via crafted,
  disallowed content.