CVE-2012-6081
Published Jan 3, 2013
Last updated 11 years ago
Overview
- Description
- Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote authenticated users with write permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory, as exploited in the wild in July 2012.
- Source
- secalert@redhat.com
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6
- Impact score
- 6.4
- Exploitability score
- 6.8
- Vector string
- AV:N/AC:M/Au:S/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Social media
- Hype score
- Not currently trending
Evaluator
- Comment
- Per: http://cwe.mitre.org/data/definitions/434.html 'CWE-434: Unrestricted Upload of File with Dangerous Type'
- Impact
- -
- Solution
- -
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:moinmo:moinmoin:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AEA7AEF9-AD64-401A-BF0D-7549E6CEF030", "versionEndIncluding": "1.9.5" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C3BA7ACF-4304-4E0A-BBEC-233684B17BED" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DF3DB6BE-F00B-42A4-A121-60A3D7A65E55" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C06C7F65-58B4-4B78-8B01-2896A87B2AAA" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DD692C09-2787-4CBD-80F8-7872B76E72C6" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1C00A124-C693-41EB-A0A9-87FA2C7D0B01" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9C0513D2-EF88-4C7E-9877-603F99FD7D97" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E480D12C-BC4E-475D-8C5D-53E7DE900596" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:0.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6B18E3CC-DEA6-42B0-8D08-8F41031B0042" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:0.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3A353553-4720-4457-8FBA-9F2808507492" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:0.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B0ECE1A5-0714-467D-A0DD-19C94359D21C" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:0.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1619929D-C06A-460B-9BD6-815B0FB2E319" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B5C75D53-AAA5-4BC4-A464-D525A7507120" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D7BF1B63-7FBC-47CD-BE8E-509331B60B8B" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "010A1332-BD8C-49D9-A742-632571EB3E1F" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1A1A6994-D9C8-4D80-82DC-CCC84891055F" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "136BA0A5-98FE-48A8-BD5F-E163ECF351D1" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "98C74029-698A-4413-9BE6-43AE04E232C4" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "38629A9E-B8B3-4513-A271-D0F9C9B01940" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8EC6287C-7EF7-41C7-BA54-CE667DF402A6" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F800E619-F48D-47E7-A776-878099C198B2" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.3.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "42BEB861-A3C9-4D92-B042-7CC17E6F0FC4" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.3.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "742D85DB-0E6B-45E2-99A1-7140CDBCEED7" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.3.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D915ED2B-97BF-427E-9F1F-F5A55DB59527" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.3.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "830C376B-8F3A-4695-B0E1-56DFC8E36050" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.3.5:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DE674DBF-3B8B-4F0C-9D3F-2331A533FA53" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "759E9B75-1B72-4324-940E-C69E6C59E392" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "853D71B8-E563-4730-9DD5-EFF8CF87B413" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.5.0:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "05461641-A9C4-4006-8442-98520DA23EC8" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.5.0:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DF724DF0-8C5F-4F77-88C8-1FB521FD5A06" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.5.0:beta3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A58BEC46-0FEB-4EE0-B380-0D39FCFE1E7B" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.5.0:beta4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7ABF88D5-561A-4CCB-B323-A736953914CD" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.5.0:beta5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2DA1B94A-2EDC-43F8-83F1-E10A7890B3C1" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.5.0:beta6:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6CC202ED-E219-42CE-BC46-F424C714F316" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.5.0:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "92056276-DBDC-432A-905F-D3C8AD231F7F" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7779A40E-B882-439D-9176-DAF1AD369EDB" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7A4B4F98-2002-448B-A6A8-D9BA8737B723" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.5.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B8376370-2978-4E95-AB19-07197330AD6C" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.5.3:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "929867E4-9A4F-4B99-BF61-8BB1DB28962A" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.5.3:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B51BFA62-E867-4919-9B14-2C480009FC62" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.5.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E0510B94-903C-4B51-97A6-D13D999D87C2" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.5.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "30A445D9-11DD-4DF7-AABD-539F432EC803" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.5.5:a:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D346F561-44A5-412C-8551-7A7F4E537721" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.5.5:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "69A4F9E1-BFE4-4326-8C86-F2E8BE58F45F" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.5.5a:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "70805F86-C038-4310-BBCE-53E3C0739A3E" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.5.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7D9DF1DB-047A-4FF3-90E4-3C5B12934AD2" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.5.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "08737344-5992-4BB7-9F0D-CCD5E0F19B63" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.5.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4B2291F8-480B-40D5-AE14-FDC78435CD37" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E6CD4382-1412-4D82-9094-57E90B8C9C23" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.6.0:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8DDC6900-5361-4BAE-9164-D0EAA5170B61" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.6.0:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "131BDB4E-3C1A-4FA4-84E0-37508559513E" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.6.0:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E7BA7A7B-1DDB-427E-A9F1-89EAB2A76956" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.6.0:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "61B4FA65-C2FE-47BF-80D4-5ED09BC961B9" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "23A64B6E-48D4-4743-97E3-C1EC6C1A2EBE" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.6.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "76F8DDF8-D923-40FE-9D47-F676A04BD908" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.6.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E5BE42E1-8CDC-47B8-AC07-E9415542AD5B" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.6.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "52857288-A7F7-40EA-9A72-01A6B6551FE5" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F2863EC4-FAD5-4456-983F-F3676E887CF7" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.7.0:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3A53F3F1-19B4-4A79-BE8B-544890E19C7E" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.7.0:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "00911CD0-5F85-421A-8430-40AC85F63019" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.7.0:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B1677575-A194-4F04-9ABA-F64EDAAB446F" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.7.0:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0CABF9F6-83B1-4193-AA89-A8DE14435215" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.7.0:rc3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AACD410A-08AC-4241-A764-B528A0C9BC44" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "20921AD9-B2A9-417F-B83D-6013CD9F662E" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.7.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DB78616E-55AB-4C8A-874B-7DCF6E755E52" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.7.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9B42EBD4-6773-4DD3-B93C-703076D2BAD7" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.8.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2584941F-5FE8-4636-B878-50CC5D4CC258" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.8.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D06004B5-966B-48F5-87B4-7005DBC86D63" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.8.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2C2C741A-220A-454C-8D21-6459DB2D67E8" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.8.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FB916ACA-0E61-4C6B-84BE-8BD27AE766AD" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.8.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DCDE917F-0AFB-431C-A0B2-CCC86946E7FE" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.8.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BF7C0C0F-A970-4CB9-BC6D-131253CB8749" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.8.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "37002B23-E8E4-43AB-A6D7-BC747BE1A8D3" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.8.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1A43AEE5-6540-4264-A956-391D8CC1212D" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.9.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BAA73028-4193-49E9-B017-F1F27075FDDE" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.9.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2B6FF2CB-A7F2-4E74-8B95-0C7BA3DE47AD" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.9.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1B7C3A9E-1655-436F-94FF-390D44926A28" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.9.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D8434905-3540-4ADE-8223-251FFABD31D9" }, { "criteria": "cpe:2.3:a:moinmo:moinmoin:1.9.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AD68516B-3E72-41F4-8BD1-60A98FC1C9E3" } ], "operator": "OR" } ] } ]