The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorized include files via unknown vectors.
References
Link | Resource |
---|---|
http://hg.moinmo.in/moin/1.6/rev/35ff7a9b1546 | Vendor Advisory |
http://osvdb.org/48877 | |
http://moinmo.in/SecurityFixes | Vendor Advisory |
Configurations
Information
Published : 2009-03-29 18:30
Updated : 2009-03-29 21:00
NVD link : CVE-2008-6548
Mitre link : CVE-2008-6548
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
moinmo
- moinmoin