Description

Possible XSS HTML injection (wiki search box top right and fileupload rename field)

Steps to reproduce

Input "<script>alert('test')</script>" into search box and klick title or text

Example

http://test.wikiwikiweb.de/?action=fullsearch&context=180&value=%3Cscript+%3Ealert%28%27Cookiedata%3A+%27+%2B+document.cookie%29%3C%2Fscript%3E&titlesearch=Titel

Component selection

Details

MoinMoin Version

1.6.0alpha (0803e5da055d)

OS and Version

Debian Linux Stable

Python Version

Python 2.3.5

Server Setup

TwistedWeb

Server Details

Language you are using the wiki in (set in the browser/UserPreferences)

Workaround

Discussion

Plan


CategoryMoinMoinBugFixed

MoinMoin: MoinMoinBugs/1.6devSiteSearchFileUploadXSS (last edited 2007-10-29 19:20:56 by localhost)