CVE-2007-0901Medium▾ SunlitMoinMoin Cross-Site Scripting (XSS) vulnerability via hitcounts and general parameters
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.7%
1.7% → 1.8%
Multiple cross-site scripting (XSS) vulnerabilities in Info pages in MoinMoin 1.5.7 allow remote attackers to inject arbitrary web script or HTML via the (1) hitcounts and (2) general parameters, different vectors than CVE-2007-0857. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
moin < 1.5.8Upgrade to a patched release:
moin 1.5.8Connected by shared product, vendor, weakness, or advisory.
CVE-2007-0902MediumMoinMoin Insertion of Sensitive Information into Log File
CVE-2020-25074High· 8.8MoinMoin vulnerable to remote code execution via cache action
CVE-2007-2637MediumMoinMoin Improper ACL handling for calendars and includes
CVE-2004-1462HighMoinMoin Improper Access Control
CVE-2007-0857MediumMoinMoin Multiple cross-site scripting (XSS) vulnerabilities
CVE-2008-1099MediumMoinMoin Improper Access Control