Vulnerability Name: | CCN-13865 | ||||||
Published: | 2003-11-28 | ||||||
Updated: | 2003-11-28 | ||||||
Summary: | MoinMoin is vulnerable to cross-site scripting. A remote attacker could embed malicious code within a specially-crafted URL request, which would be executed in the victim's Web browser within the security context of the hosting site, once the link is clicked. An attacker could exploit this vulnerability to steal the victim's cookie-based authentication credentials and possibly obtain other sensitive information. | ||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||
CVSS v2 Severity: | 2.6 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N) 2.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||
Vulnerability Consequences: | Obtain Information | ||||||
References: | Source: CCN Type: BID-9135 MoinMoin Unspecified Cross-Site Scripting Vulnerability Source: XF Type: UNKNOWN moinmoin-xss(13865) | ||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||
BACK |