← Back

CVE-2012-6081

nvd nist
Published: Jan 3, 2013Modified: Apr 29, 2026

JSON object

Loading...
6.0
Vector
AV:N/AC:M/Au:S/C:P/I:P/A:P
Exploitability: 6.8 / Impact: 6.4
Source: NVD

Description

Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote authenticated users with write permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory, as exploited in the wild in July 2012.

Affected (79)

Products: Moinmo: Moinmoin
1 product
Moinmoin
Configuration A
79 vulnerable
Vulnerable SoftwareAffected Versions
Moinmo
Up to 1.9.5
Version 0.10
Version 0.11
Version 0.1
Version 0.2
Version 0.3
Version 0.4
Version 0.5
Version 0.6
Version 0.7
Version 0.8
Version 0.9
Version 1.0
Version 1.1
Version 1.2.1
Version 1.2.2
Version 1.2.3
Version 1.2.4
Version 1.2
Version 1.3.0
Version 1.3.1
Version 1.3.2
Version 1.3.3
Version 1.3.4
Version 1.3.5
Version 1.3.5 rc1
Version 1.4
Version 1.5.0
Version 1.5.0 beta1
Version 1.5.0 beta2
Version 1.5.0 beta3
Version 1.5.0 beta4
Version 1.5.0 beta5
Version 1.5.0 beta6
Version 1.5.0 rc1
Version 1.5.1
Version 1.5.2
Version 1.5.3
Version 1.5.3 rc1
Version 1.5.3 rc2
Version 1.5.4
Version 1.5.5
Version 1.5.5 a
Version 1.5.5 rc1
Version 1.5.5a
Version 1.5.6
Version 1.5.7
Version 1.5.8
Version 1.6.0
Version 1.6.0 beta1
Version 1.6.0 beta2
Version 1.6.0 rc1
Version 1.6.0 rc2
Version 1.6.1
Version 1.6.2
Version 1.6.3
Version 1.6.4
Version 1.7.0
Version 1.7.0 beta1
Version 1.7.0 beta2
Version 1.7.0 rc1
Version 1.7.0 rc2
Version 1.7.0 rc3
Version 1.7.1
Version 1.7.2
Version 1.7.3
Version 1.8.0
Version 1.8.1
Version 1.8.2
Version 1.8.3
Version 1.8.4
Version 1.8.6
Version 1.8.7
Version 1.8.8
Version 1.9.0
Version 1.9.1
Version 1.9.2
Version 1.9.3
Version 1.9.4

References (26)

Source: secalert@redhat.com
ExploitPatch
Source: secalert@redhat.com
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.