CVE-2008-3381: XSS
Multiple cross-site scripting (XSS) vulnerabilities in macro/AdvancedSearch.py in moin (and MoinMoin) 1.6.3 and 1.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Other sources
Multiple cross-site scripting (XSS) vulnerabilities in macro/AdvancedSearch.py in moin (and MoinMoin) 1.6.3 and 1.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3381?
CVE-2008-3381 is classified as a high severity vulnerability due to its potential for allowing remote injection of malicious scripts.
How do I fix CVE-2008-3381?
To fix CVE-2008-3381, you should upgrade to version 1.7.1 or later if you are using 1.7.0, or upgrade to version 1.6.4 or later if you are using 1.6.3 or older.
Which versions are affected by CVE-2008-3381?
Versions 1.6.3 and 1.7.0 of MoinMoin are vulnerable to CVE-2008-3381.
What types of attacks can be executed due to CVE-2008-3381?
CVE-2008-3381 allows remote attackers to execute cross-site scripting (XSS) attacks, potentially leading to session hijacking or malicious actions performed on behalf of the user.
Is MoinMoin still maintained to address vulnerabilities like CVE-2008-3381?
MoinMoin has ongoing support, but it's essential to use the latest versions to ensure all known vulnerabilities, including CVE-2008-3381, are patched.