PT-2013-1877 · Moinmoin · Moinmoin

Jamie Strandboge

+1

·

Published

2013-01-03

·

Updated

2022-05-17

·

CVE-2012-6081

CVSS v2.0

6.0

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MoinMoin versions prior to 1.9.6
Description The issue allows remote authenticated users with write permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory. This has been exploited in the wild in July 2012. The vulnerabilities are found in the twikidraw (action/twikidraw.py) and anywikidraw (action/anywikidraw.py) actions.
Recommendations For versions prior to 1.9.6, update to version 1.9.6 or later to resolve the issue. As a temporary workaround, consider restricting write permissions or disabling the action/twikidraw.py and action/anywikidraw.py actions until a patch is applied. Avoid using these actions to upload files with executable extensions until the issue is resolved.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-6081
DSA-2593-1
GHSA-M2C4-JGMM-FVQ3
PYSEC-2013-6

Affected Products

Moinmoin