Release date:
Updated on:
Affected Systems:
MoinMoin Wiki Engine 1.9.3
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57089
CVE (CAN) ID: CVE-2012-6082
MoinMoin is a Wiki clone (Wiki: WikiClone) implemented by Python. The earliest version is based on Wiki: PikiPiki.
Theme/_ init _ in MoinMoin 1.9.5 __. the rsslink function in The py operation does not properly process the page. page_name, which has the XSS vulnerability, allows remote attackers to inject arbitrary Web scripts or HTML files to the file name in the rss link.
<* Source: vendor
Link: https://bugzilla.RedHat.com/show_bug.cgi? Id = 890907
Http://web.nvd.nist.gov/view/vuln/detail? VulnId = CVE-2012-6082
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
MoinMoin
--------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://moinmo.in/