The default configuration of cfg.packagepages_actions_excluded in MoinMoin before 1.8.7 does not prevent unsafe package actions, which has unspecified impact and attack vectors.
Weaknesses in this category are typically introduced during the configuration of the software.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/56595 | vdb entry |
http://www.openwall.com/lists/oss-security/2010/02/15/2 | mailing list |
http://hg.moinmo.in/moin/1.8/raw-file/1.8.7/docs/CHANGES | |
http://moinmo.in/MoinMoinRelease1.8 | |
http://www.debian.org/security/2010/dsa-2014 | vendor advisory |
http://secunia.com/advisories/38903 | third party advisory |
http://www.vupen.com/english/advisories/2010/0600 | vdb entry |