Skip to content
Noroxi

twiki records

30 published records for vendor twiki.

All records

30 records
  • The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string.

    CriticalCVSS 10.0WeaponizedEPSS 62%

    twiki · twikiMar 1, 2005

  • Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the de

    CriticalCVSS 9.1WeaponizedEPSS 56%

    twiki · twikiFeb 17, 2020

  • The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary code via shell metacha

    HighCVSS 7.5WeaponizedEPSS 71%

    twiki · twikiSep 16, 2005

  • Eval injection vulnerability in TWiki before 4.2.4 allows remote attackers to execute arbitrary Perl code via the %SEARCH{}% variable.

    CriticalCVSS 10.0Proof of conceptEPSS 5%

    twiki · twikiDec 9, 2008

  • TWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' parameter value containin

    CriticalCVSS 9.8No exploitEPSS 5%

    twiki · twikiNov 7, 2019

  • TWiki allows arbitrary shell command execution via the Include function

    CriticalCVSS 9.8No exploitEPSS 3%

    twiki · twikiNov 1, 2019

  • CVE-2006-6071
    37Monitor

    TWiki 4.0.5 and earlier, when running under Apache 1.3 using ApacheLogin with sessions and "ErrorDocument 401" redirects to a valid wiki top

    CriticalCVSS 9.0No exploitEPSS 2%

    twiki · twikiDec 1, 2006

  • CVE-2014-7237
    33Monitor

    lib/TWiki/Sandbox.pm in TWiki 6.0.0 and earlier, when running on Windows, allows remote attackers to bypass intended access restrictions and

    MediumCVSS 6.8No exploitEPSS 20%

    twiki · twikiOct 15, 2014

  • CVE-2012-6330
    31Monitor

    The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows remote attackers to c

    MediumCVSS 5.0Proof of conceptEPSS 36%

    twiki · twikiJan 4, 2013

  • CVE-2006-3819
    31Monitor

    Eval injection vulnerability in the configure script in TWiki 4.0.0 through 4.0.4 allows remote attackers to execute arbitrary Perl code via

    HighCVSS 7.5Proof of conceptEPSS 4%

    twiki · twikiJul 26, 2006

  • CVE-2005-0516
    31Monitor

    The ImageGalleryPlugin (ImageGalleryPlugin.pm) in Twiki allows remote attackers to execute arbitrary commands via certain commands that gene

    HighCVSS 7.5No exploitEPSS 2%

    twiki · imagegallerypluginFeb 23, 2005

  • CVE-2006-1386
    31Monitor

    The (1) rdiff and (2) preview scripts in TWiki 4.0 and 4.0.1 ignore access control settings, which allows remote attackers to read restricte

    HighCVSS 7.5No exploitEPSS 2%

    twiki · twikiMar 26, 2006

  • CVE-2008-3195
    29Monitor

    Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide is skipped, allows r

    MediumCVSS 6.8Proof of conceptEPSS 8%

    twiki · twikiSep 18, 2008

  • CVE-2009-4898
    27Monitor

    Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.2 allows remote attackers to hijack the authentication of arbitrary user

    MediumCVSS 6.8No exploitEPSS 1%

    twiki · twikiSep 7, 2010

  • CVE-2008-4998
    27Monitor

    postinst in twiki 4.1.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/twiki temporary file.

    MediumCVSS 6.9No exploitEPSS 0%

    twiki · twikiNov 7, 2008

  • bin/statistics in TWiki 6.0.2 allows cross-site scripting (XSS) via the webs parameter.

    MediumCVSS 6.1No exploitEPSS 2%

    twiki · twikiMar 21, 2019

  • CVE-2009-1339
    24Monitor

    Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.1 allows remote authenticated users to hijack the authentication of arbi

    MediumCVSS 6.0No exploitEPSS 1%

    twiki · twikiApr 30, 2009

  • CVE-2006-4294
    21Monitor

    Directory traversal vulnerability in viewfile in TWiki 4.0.0 through 4.0.4 allows remote attackers to read arbitrary files via a ..

    MediumCVSS 5.0Proof of conceptEPSS 4%

    twiki · twikiSep 8, 2006

  • CVE-2007-5193
    20Monitor

    The default configuration for twiki 4.1.2 on Debian GNU/Linux, and possibly other operating systems, specifies the work area directory (cfg{

    MediumCVSS 5.0No exploitEPSS 2%

    debian · debian linuxOct 4, 2007

  • CVE-2006-2942
    20Monitor

    TWiki 4.0.0, 4.0.1, and 4.0.2 allows remote attackers to gain Twiki administrator privileges via a TWiki.TWikiRegistration form with a modif

    MediumCVSS 5.1No exploitEPSS 2%

    twiki · twikiJun 20, 2006

  • CVE-2011-3010
    19Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in TWiki before 5.1.0 allow remote attackers to inject arbitrary web script or HTML via

    MediumCVSS 4.3Proof of conceptEPSS 5%

    twiki · twikiSep 30, 2011

  • CVE-2010-3841
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in lib/TWiki.pm in TWiki before 5.0.1 allow remote attackers to inject arbitrary web scr

    MediumCVSS 4.3Proof of conceptEPSS 3%

    twiki · twikiOct 18, 2010

  • CVE-2011-1838
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in TemplateLogin.pm in TWiki before 5.0.2 allow remote attackers to inject arbitrary web

    MediumCVSS 4.3Proof of conceptEPSS 3%

    twiki · twikiMay 20, 2011

  • CVE-2008-5304
    18Monitor

    Cross-site scripting (XSS) vulnerability in TWiki before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via the %URLPA

    MediumCVSS 4.3Proof of conceptEPSS 2%

    twiki · twikiDec 9, 2008

  • CVE-2012-0979
    18Monitor

    Cross-site scripting (XSS) vulnerability in TWiki allows remote attackers to inject arbitrary web script or HTML via the organization field

    MediumCVSS 4.3No exploitEPSS 2%

    twiki · twikiFeb 2, 2012