CVE-2007-0857: XSS
Published Feb 8, 2007
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin before 1.5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the page info, or the page name in a (2) AttachFile, (3) RenamePage, or (4) LocalSiteMap action.
Affected Software
12 affected componentsFixes available
pip/moin<1.5.7
1.5.7
MoinMoin MoinMoin<=1.5.6
MoinMoin MoinMoin=1.5.0
MoinMoin MoinMoin=1.5.1
MoinMoin MoinMoin=1.5.2
MoinMoin MoinMoin=1.5.3
MoinMoin MoinMoin=1.5.3_rc1
MoinMoin MoinMoin=1.5.3_rc2
MoinMoin MoinMoin=1.5.4
MoinMoin MoinMoin=1.5.5
MoinMoin MoinMoin=1.5.5_rc1
MoinMoin MoinMoin=1.5.5a
Remediation
Patch Available
Event History
Feb 8, 2007
CVE Published
06:28 PM
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
May 1, 2022
Advisory Published
via GitHub·05:47 PM
Frequently Asked Questions
1
What is the severity of CVE-2007-0857?
CVE-2007-0857 is classified as a medium severity vulnerability due to its potential to exploit cross-site scripting attacks.
2
How do I fix CVE-2007-0857?
To fix CVE-2007-0857, you should upgrade MoinMoin to version 1.5.7 or later.
3
What versions are affected by CVE-2007-0857?
CVE-2007-0857 affects all MoinMoin versions prior to 1.5.7.
4
Can CVE-2007-0857 be exploited remotely?
Yes, CVE-2007-0857 can be exploited remotely by an attacker through crafted inputs.
5
What types of actions are vulnerable in CVE-2007-0857?
The vulnerable actions in CVE-2007-0857 include AttachFile, RenamePage, and LocalSiteMap, among others.