CVE-2007-0902Medium▾ SunlitMoinMoin Insertion of Sensitive Information into Log File
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.3%
1.3% → 1.4%
An information leak was discovered in MoinMoin's debug reporting version 1.5.7, which could expose information about the versions of software running on the host system. MoinMoin administrators can add "show_traceback=0" to their site configurations to disable debug tracebacks.
moin >= 1.5.7, < 1.5.8Upgrade to a patched release:
moin 1.5.8Connected by shared product, vendor, weakness, or advisory.
CVE-2007-0901MediumMoinMoin Cross-Site Scripting (XSS) vulnerability via hitcounts and general parameters
CVE-2007-2637MediumMoinMoin Improper ACL handling for calendars and includes
CVE-2020-25074High· 8.8MoinMoin vulnerable to remote code execution via cache action
CVE-2004-1462HighMoinMoin Improper Access Control
CVE-2007-0857MediumMoinMoin Multiple cross-site scripting (XSS) vulnerabilities
CVE-2008-1099MediumMoinMoin Improper Access Control