CVE-2010-0667

medium
Published 2010-02-26 · Modified 2024-04-01
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v2
5.0
VIR risk
5.0

Description

MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable is set, which allows remote attackers to obtain sensitive information via unspecified vectors.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://secunia.com/advisories/38242

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://moinmo.in/SecurityFixes

Package impact

EcosystemPackageVulnerableFixed
python PyPImoin>=1.9,<1.9.11.9.1

Application impact

VendorProductVersionsFixed
moinmomoinmoin1.9.0

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.