HTTP: MoinMoin Arbitrary File Upload Attempt Detected

This signature detects attempts to exploit a known vulnerability against MoinMoin. Attackers can upload arbitrary files on the targeted system and gain unauthorized remote access.

Extended Description

Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote authenticated users with write permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory, as exploited in the wild in July 2012.

Affected Products

Moinmo moinmoin

References

BugTraq: 57082

CVE: CVE-2012-6081

Short Name
HTTP:MOIN-FILE-UPLOAD
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Arbitrary Attempt CVE-2012-6081 Detected File MoinMoin Upload bid:57082
Release Date
08/26/2016
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
Vendors

Moinmo

CVSS Score

6.0

Found a potential security threat?