Moderate severityNVD Advisory· Published Jan 3, 2013· Updated Apr 29, 2026
CVE-2012-6080
CVE-2012-6080
Description
Directory traversal vulnerability in the _do_attachment_move function in the AttachFile action (action/AttachFile.py) in MoinMoin 1.9.3 through 1.9.5 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a file name.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
moinPyPI | >= 1.9.3, < 1.9.6 | 1.9.6 |
Affected products
3Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
17- hg.moinmo.in/moin/1.9/rev/3c27131a3c52nvdPatchWEB
- moinmo.in/SecurityFixesnvdVendor AdvisoryWEB
- secunia.com/advisories/51663nvdVendor Advisory
- secunia.com/advisories/51676nvdVendor Advisory
- secunia.com/advisories/51696nvdVendor Advisory
- github.com/advisories/GHSA-v33q-2xcj-4f3mghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2012-6080ghsaADVISORY
- ubuntu.com/usn/usn-1680-1nvdWEB
- www.debian.org/security/2012/dsa-2593nvdWEB
- www.openwall.com/lists/oss-security/2012/12/30/6nvdWEB
- bugs.launchpad.net/ubuntu/+source/moin/+bug/1094599nvdWEB
- github.com/pypa/advisory-database/tree/main/vulns/moin/PYSEC-2013-5.yamlghsaWEB
- web.archive.org/web/20130513231719/http://secunia.com/advisories/51663ghsaWEB
- web.archive.org/web/20151017045319/http://secunia.com/advisories/51696ghsaWEB
- web.archive.org/web/20151104192815/http://secunia.com/advisories/51676ghsaWEB
- web.archive.org/web/20200228145410/http://www.securityfocus.com/bid/57076ghsaWEB
- www.securityfocus.com/bid/57076nvd
News mentions
0No linked articles in our index yet.