moinwiki / moin

MoinMoin Wiki Development (2.0+), unstable, for production please use 1.9.x.
https://moinmo.in/
Other
306 stars 92 forks source link

systematic security review(s) #318

Open ThomasWaldmann opened 11 years ago

ThomasWaldmann commented 11 years ago

Original report by Thomas Waldmann (Bitbucket: thomaswaldmann, GitHub: thomaswaldmann).


Some hints (not everything applies to Python, but you get the idea):

http://cwe.mitre.org/top25/index.html

RogerHaase commented 2 years ago

Google led me to ZAP: https://www.zaproxy.org/

GitHub has suppport: https://github.com/marketplace/actions/owasp-zap-baseline-scan

ZAP can be installed and run against the built-in server. The test wiki had auto registration turned off, one item with one bad link.

ZAP found 9 alerts: 5 medium risk, 3 low risk, 1 informational.

Any suggestions for a better tool?

ReimarBauer commented 1 year ago

I have a similiar issue in my project, a colleague mentioned there https://w3af.org/ we have not compared both. seems that it is py 2.7 based.