header-logo
Suggest Exploit
vendor:
MoinMoin
by:
cr3dz
8,8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: MoinMoin
Affected Version From: 1.9.9
Affected Version To: 1.9.10
Patch Exists: Yes
Related CWE: N/A
CPE: a:moinmoin:moinmoin
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Linux, Windows, Mac
2020

MoinMoin Remote Arbitrary Command Execution

MoinMoin is a popular wiki software written in Python. A vulnerability exists in the software which allows an attacker to execute arbitrary commands on the server. This exploit is achieved by sending a specially crafted request to the server which contains malicious code. The code is then executed on the server, allowing the attacker to gain access to the system.

Mitigation:

The best way to mitigate this vulnerability is to upgrade to the latest version of MoinMoin. Additionally, it is recommended to use a web application firewall to detect and block malicious requests.
Source

Exploit-DB raw data: