Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2012-4404
Description:security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote authenticated users with virtual group membership to be treated as a member of the group.
Test IDs: 1.3.6.1.4.1.25623.1.0.108326   1.3.6.1.4.1.25623.1.0.72167   1.3.6.1.4.1.25623.1.0.864723   1.3.6.1.4.1.25623.1.0.108327   1.3.6.1.4.1.25623.1.0.864715   1.3.6.1.4.1.25623.1.0.71866  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2012-4404
50474
http://secunia.com/advisories/50474
50496
http://secunia.com/advisories/50496
50885
http://secunia.com/advisories/50885
DSA-2538
http://www.debian.org/security/2012/dsa-2538
USN-1604-1
http://www.ubuntu.com/usn/USN-1604-1
[oss-security] 20120904 CVE request: moinmoin incorrect ACL evaluation for virtual groups
http://www.openwall.com/lists/oss-security/2012/09/04/4
[oss-security] 20120904 Re: CVE request: moinmoin incorrect ACL evaluation for virtual groups
http://www.openwall.com/lists/oss-security/2012/09/05/2
http://hg.moinmo.in/moin/1.9/rev/7b9f39289e16
http://hg.moinmo.in/moin/1.9/rev/7b9f39289e16
http://moinmo.in/SecurityFixes
http://moinmo.in/SecurityFixes




© 1998-2025 E-Soft Inc. All rights reserved.