MoinMoin before 20070507 does not properly enforce ACLs for calendars and includes, which allows remote attackers to read certain pages via unspecified vectors.
Link | Tags |
---|---|
http://osvdb.org/36269 | vdb entry |
http://secunia.com/advisories/29262 | third party advisory |
http://secunia.com/advisories/25208 | third party advisory patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/34474 | vdb entry |
http://www.ubuntu.com/usn/usn-458-1 | patch vendor advisory |
http://www.debian.org/security/2008/dsa-1514 | vendor advisory |