>> MoinMoin Restrictions Bypass and Privilege Escalation Vulnerabilities
Title : MoinMoin Restrictions Bypass and Privilege Escalation Vulnerabilities VUPEN ID : VUPEN/ADV-2008-1307 CVE ID : CVE-2008-1937 - CVE-2008-6603
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-04-21
Technical Description
Two vulnerabilities have been identified in MoinMoin, which could be exploited by malicious users to bypass security checks and gain elevated privileges.
The first issue is caused by errors in the userform processing, which could be exploited to bypass ACL restrictions and obtain superuser privileges.
The second vulnerability is caused by an error in the ACL processing when "acl_hierarchic=True", which could be exploited to bypass security restrictions.