CVE-2009-1482

Source
https://cve.org/CVERecord?id=CVE-2009-1482
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2009-1482.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2009-1482
Aliases
Downstream
Withdrawn
2024-06-30T15:59:08.463315Z
Published
2009-04-29T18:30:00Z
Modified
2024-06-04T04:00:19Z
Summary
[none]
Details

Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin 1.8.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) an AttachFile sub-action in the errormsg function or (2) multiple vectors related to package file errors in the uploadform function, different vectors than CVE-2009-0260.

References

Affected packages

Debian:10 / moin

Package

Name
moin
Purl
pkg:deb/debian/moin?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.8.3-1

Ecosystem specific

{
    "urgency": "low"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2009-1482.json"