id: PYSEC-2013-7 details: 'Multiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote authenticated users with write permissions to overwrite arbitrary files via unspecified vectors. NOTE: this can be leveraged with CVE-2012-6081 to execute arbitrary code.' affected: - package: name: moin ecosystem: PyPI purl: pkg:pypi/moin ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 1.9.6 versions: - 1.8.4 - 1.8.5 - 1.8.6 - 1.8.7 - 1.9.0 - 1.9.1 - 1.9.2 - 1.9.3 - 1.9.4 - 1.9.5 references: - type: ADVISORY url: http://secunia.com/advisories/51696 - type: WEB url: http://hg.moinmo.in/moin/1.9/rev/7e7e1cbb9d3f - type: WEB url: http://www.openwall.com/lists/oss-security/2012/12/29/6 - type: WEB url: http://moinmo.in/MoinMoinRelease1.9 - type: WEB url: http://www.openwall.com/lists/oss-security/2012/12/30/4 - type: WEB url: https://bugs.launchpad.net/ubuntu/+source/moin/+bug/1094599 - type: WEB url: http://moinmo.in/SecurityFixes - type: ADVISORY url: http://www.debian.org/security/2012/dsa-2593 - type: WEB url: http://ubuntu.com/usn/usn-1680-1 - type: ADVISORY url: https://github.com/advisories/GHSA-6gx4-29v9-g9q5 aliases: - CVE-2012-6495 - GHSA-6gx4-29v9-g9q5 modified: "2021-07-05T00:01:23.010630Z" published: "2013-01-03T01:55:00Z"