CVE-2012-6495: Path Traversal
Multiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote authenticated users with write permissions to overwrite arbitrary files via unspecified vectors. NOTE: this can be leveraged with CVE-2012-6081 to execute arbitrary code.
Other sources
Multiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote authenticated users with write permissions to overwrite arbitrary files via unspecified vectors. NOTE: this can be leveraged with CVE-2012-6081 to execute arbitrary code.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-6495?
CVE-2012-6495 has been classified as a high-severity vulnerability due to the potential for unauthorized file overwrites.
How do I fix CVE-2012-6495?
The recommended solution for CVE-2012-6495 is to upgrade to MoinMoin version 1.9.6 or later.
What types of vulnerabilities does CVE-2012-6495 include?
CVE-2012-6495 includes multiple directory traversal vulnerabilities that allow remote authenticated users to overwrite arbitrary files.
Which versions of MoinMoin are affected by CVE-2012-6495?
CVE-2012-6495 affects all MoinMoin versions prior to 1.9.6.
Who is impacted by CVE-2012-6495?
Remote authenticated users with write permissions are impacted by CVE-2012-6495, as they can exploit the vulnerabilities.