Back to Database
Status published
High
CVE-2010-0717
The default configuration of cfg.packagepages_actions_excluded in MoinMoin before 1.8.7 does...
Vulnerability Description
The default configuration of cfg.packagepages_actions_excluded in MoinMoin before 1.8.7 does not prevent unsafe package actions, which has unspecified impact and attack vectors.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-0717
Credits & Attribution
No credits recorded in the NVD database.
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56595
- http://www.openwall.com/lists/oss-security/2010/02/15/2
- http://hg.moinmo.in/moin/1.8/raw-file/1.8.7/docs/CHANGES
- http://moinmo.in/MoinMoinRelease1.8
- http://www.debian.org/security/2010/dsa-2014
- http://secunia.com/advisories/38903
- http://www.vupen.com/english/advisories/2010/0600
More from moinmo
View All →CVE-2020-25074
The cache action in action/cache.py in MoinMoin through 1.9.10 allows...
Critical
9.8
CVE-2017-5934
Cross-site scripting (XSS) vulnerability in the link dialogue in GUI...
Medium
6.1
CVE-2016-9119
Cross-site scripting (XSS) vulnerability in the link dialogue in GUI...
Medium
6.1
CVE-2016-7148
MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks...
Medium
6.1
CVE-2016-7146
MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks...
Medium
6.1
Affected Vendor
moinmo
View all reports →Affected Software
moinmoin
Vulnerable Versions:
0, 1.5.0, 1.5.1, 1.5.2, 1.5.3, 1.5.4, 1.5.5, 1.5.5a, 1.5.6, 1.5.7, 1.5.8, 1.6.0, 1.6.1, 1.6.2, 1.6.3, 1.6.4, 1.7.0, 1.7.1, 1.7.2, 1.7.3, 1.8.0, 1.8.1, 1.8.2, 1.8.3, 1.8.4
Timeline
Official Publish:
February 26th, 2010
Last Modified:
August 7th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.