CVE-2012-6081 EXPLOIT
6.0
MEDIUM · CVSS 2.0 · EPSS 35.3% (pctl 98)
Patch early
A public exploit exists.
Description
Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote authenticated users with write permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory, as exploited in the wild in July 2012.
Scoring
| CVSS | 6.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:S/C:P/I:P/A:P |
| EPSS | 35.35% — more likely to be exploited than 98% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2013-01-03 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| moinmo | moinmoin |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | MoinMoin - twikidraw Action Traversal Arbitrary File Upload (Metasploit) | 2013-06-24 |
| exploit-db | MoinMoin - Arbitrary Command Execution | 2013-05-08 |
References
- http://hg.moinmo.in/moin/1.9/rev/7e7e1cbb9d3f
- http://moinmo.in/MoinMoinRelease1.9
- http://moinmo.in/SecurityFixes
- http://secunia.com/advisories/51663
- http://secunia.com/advisories/51676
- http://secunia.com/advisories/51696
- http://ubuntu.com/usn/usn-1680-1
- http://www.debian.org/security/2012/dsa-2593
- http://www.exploit-db.com/exploits/25304
- http://www.openwall.com/lists/oss-security/2012/12/29/6
- http://www.openwall.com/lists/oss-security/2012/12/30/4
- http://www.securityfocus.com/bid/57082
- https://bugs.launchpad.net/ubuntu/+source/moin/+bug/1094599
- http://hg.moinmo.in/moin/1.9/rev/7e7e1cbb9d3f
- http://moinmo.in/MoinMoinRelease1.9
- http://moinmo.in/SecurityFixes
- http://secunia.com/advisories/51663
- http://secunia.com/advisories/51676
- http://secunia.com/advisories/51696
- http://ubuntu.com/usn/usn-1680-1
→ the Explorer · watch your stack · NVD