CVE-2012-6081

Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in...

Basic Information

CVE State
PUBLISHED
Reserved Date
December 06, 2012
Published Date
January 03, 2013
Last Updated
August 06, 2024
Vendor
MoinMoin
Product
MoinMoin
Description
Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote authenticated users with write permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory, as exploited in the wild in July 2012.
Tags
metasploit_scanner

CVSS Scores

CVSS v2.0

6.0

Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Exploit Status

Exploited in the Wild
Yes (2013-01-03 01:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CVE 2013-01-03 01:00:00 UTC

Scanner Integrations

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

moinmoin_twikidraw

Type: metasploit • Created: Unknown

Metasploit module for CVE-2012-6081

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Metasploit