Directory traversal vulnerability in the _do_attachment_move
function in the AttachFile action (action/AttachFile.py
) in MoinMoin 1.9.3 through 1.9.5 allows remote attackers to overwrite arbitrary files via a ..
(dot dot) in a file name.
{ "nvd_published_at": "2013-01-03T01:55:00Z", "severity": "MODERATE", "github_reviewed_at": "2024-05-01T10:53:12Z", "github_reviewed": true, "cwe_ids": [ "CWE-22" ] }