twiki kayıtları
twiki üreticisine ait 30 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 3 · %10
- Pre-auth RCE
- 11
- Düzeltme kaydı olan
- %3,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-189 Numeric Errors1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
30 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
59Planlayın | CVE-2004-1037Silahlaştırılmış | The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string.twiki · twiki | Kritik10,0 | — | %61,7 | 1 Mar 2005 |
53Planlayın | CVE-2014-7236Silahlaştırılmış | Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the detwiki · twiki · CWE-74 | Kritik9,1 | — | %55,6 | 17 Şub 2020 |
51Planlayın | CVE-2005-2877Silahlaştırılmış | The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary code via shell metachatwiki · twiki | Yüksek7,5 | — | %70,9 | 16 Eyl 2005 |
41Planlayın | CVE-2008-5305Kavram kanıtı | Eval injection vulnerability in TWiki before 4.2.4 allows remote attackers to execute arbitrary Perl code via the %SEARCH{}% variable.twiki · twiki · CWE-94 | Kritik10,0 | — | %4,6 | 9 Ara 2008 |
40Planlayın | CVE-2013-1751İstismar yok | TWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' parameter value containintwiki · twiki · CWE-20 | Kritik9,8 | — | %4,9 | 7 Kas 2019 |
40Planlayın | CVE-2005-3056İstismar yok | TWiki allows arbitrary shell command execution via the Include functiontwiki · twiki · CWE-74 | Kritik9,8 | — | %3,5 | 1 Kas 2019 |
37İzleyin | CVE-2006-6071İstismar yok | TWiki 4.0.5 and earlier, when running under Apache 1.3 using ApacheLogin with sessions and "ErrorDocument 401" redirects to a valid wiki toptwiki · twiki | Kritik9,0 | — | %2,2 | 1 Ara 2006 |
33İzleyin | CVE-2014-7237İstismar yok | lib/TWiki/Sandbox.pm in TWiki 6.0.0 and earlier, when running on Windows, allows remote attackers to bypass intended access restrictions andtwiki · twiki · CWE-264 | Orta6,8 | — | %20,1 | 15 Eki 2014 |
31İzleyin | CVE-2012-6330Kavram kanıtı | The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows remote attackers to ctwiki · twiki · CWE-189 | Orta5,0 | — | %35,7 | 4 Oca 2013 |
31İzleyin | CVE-2006-3819Kavram kanıtı | Eval injection vulnerability in the configure script in TWiki 4.0.0 through 4.0.4 allows remote attackers to execute arbitrary Perl code viatwiki · twiki | Yüksek7,5 | — | %4,1 | 26 Tem 2006 |
31İzleyin | CVE-2005-0516İstismar yok | The ImageGalleryPlugin (ImageGalleryPlugin.pm) in Twiki allows remote attackers to execute arbitrary commands via certain commands that genetwiki · imagegalleryplugin | Yüksek7,5 | — | %2,3 | 23 Şub 2005 |
31İzleyin | CVE-2006-1386İstismar yok | The (1) rdiff and (2) preview scripts in TWiki 4.0 and 4.0.1 ignore access control settings, which allows remote attackers to read restrictetwiki · twiki | Yüksek7,5 | — | %1,8 | 26 Mar 2006 |
29İzleyin | CVE-2008-3195Kavram kanıtı | Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide is skipped, allows rtwiki · twiki · CWE-22 | Orta6,8 | — | %8,3 | 18 Eyl 2008 |
27İzleyin | CVE-2009-4898İstismar yok | Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.2 allows remote attackers to hijack the authentication of arbitrary usertwiki · twiki · CWE-352 | Orta6,8 | — | %0,6 | 7 Eyl 2010 |
27İzleyin | CVE-2008-4998İstismar yok | postinst in twiki 4.1.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/twiki temporary file.twiki · twiki · CWE-59 | Orta6,9 | — | %0,3 | 7 Kas 2008 |
24İzleyin | CVE-2018-20212İstismar yok | bin/statistics in TWiki 6.0.2 allows cross-site scripting (XSS) via the webs parameter.twiki · twiki · CWE-79 | Orta6,1 | — | %1,6 | 21 Mar 2019 |
24İzleyin | CVE-2009-1339İstismar yok | Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.1 allows remote authenticated users to hijack the authentication of arbitwiki · twiki · CWE-352 | Orta6,0 | — | %0,7 | 30 Nis 2009 |
21İzleyin | CVE-2006-4294Kavram kanıtı | Directory traversal vulnerability in viewfile in TWiki 4.0.0 through 4.0.4 allows remote attackers to read arbitrary files via a ..twiki · twiki | Orta5,0 | — | %3,9 | 8 Eyl 2006 |
20İzleyin | CVE-2007-5193İstismar yok | The default configuration for twiki 4.1.2 on Debian GNU/Linux, and possibly other operating systems, specifies the work area directory (cfg{debian · debian linux | Orta5,0 | — | %1,6 | 4 Eki 2007 |
20İzleyin | CVE-2006-2942İstismar yok | TWiki 4.0.0, 4.0.1, and 4.0.2 allows remote attackers to gain Twiki administrator privileges via a TWiki.TWikiRegistration form with a modiftwiki · twiki | Orta5,1 | — | %1,6 | 20 Haz 2006 |
19İzleyin | CVE-2011-3010Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in TWiki before 5.1.0 allow remote attackers to inject arbitrary web script or HTML via twiki · twiki · CWE-79 | Orta4,3 | — | %5,5 | 30 Eyl 2011 |
18İzleyin | CVE-2010-3841Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in lib/TWiki.pm in TWiki before 5.0.1 allow remote attackers to inject arbitrary web scrtwiki · twiki · CWE-79 | Orta4,3 | — | %3,1 | 18 Eki 2010 |
18İzleyin | CVE-2011-1838Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in TemplateLogin.pm in TWiki before 5.0.2 allow remote attackers to inject arbitrary webtwiki · twiki · CWE-79 | Orta4,3 | — | %2,7 | 20 May 2011 |
18İzleyin | CVE-2008-5304Kavram kanıtı | Cross-site scripting (XSS) vulnerability in TWiki before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via the %URLPAtwiki · twiki · CWE-79 | Orta4,3 | — | %2,2 | 9 Ara 2008 |
18İzleyin | CVE-2012-0979İstismar yok | Cross-site scripting (XSS) vulnerability in TWiki allows remote attackers to inject arbitrary web script or HTML via the organization field twiki · twiki · CWE-79 | Orta4,3 | — | %2,0 | 2 Şub 2012 |
- CVE-2004-103759Planlayın
The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string.
KritikCVSS 10,0SilahlaştırılmışEPSS %62twiki · twiki1 Mar 2005
- CVE-2014-723653Planlayın
Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the de
KritikCVSS 9,1SilahlaştırılmışEPSS %56twiki · twiki17 Şub 2020
- CVE-2005-287751Planlayın
The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary code via shell metacha
YüksekCVSS 7,5SilahlaştırılmışEPSS %71twiki · twiki16 Eyl 2005
- CVE-2008-530541Planlayın
Eval injection vulnerability in TWiki before 4.2.4 allows remote attackers to execute arbitrary Perl code via the %SEARCH{}% variable.
KritikCVSS 10,0Kavram kanıtıEPSS %5twiki · twiki9 Ara 2008
- CVE-2013-175140Planlayın
TWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' parameter value containin
KritikCVSS 9,8İstismar yokEPSS %5twiki · twiki7 Kas 2019
- CVE-2005-305640Planlayın
TWiki allows arbitrary shell command execution via the Include function
KritikCVSS 9,8İstismar yokEPSS %3twiki · twiki1 Kas 2019
- CVE-2006-607137İzleyin
TWiki 4.0.5 and earlier, when running under Apache 1.3 using ApacheLogin with sessions and "ErrorDocument 401" redirects to a valid wiki top
KritikCVSS 9,0İstismar yokEPSS %2twiki · twiki1 Ara 2006
- CVE-2014-723733İzleyin
lib/TWiki/Sandbox.pm in TWiki 6.0.0 and earlier, when running on Windows, allows remote attackers to bypass intended access restrictions and
OrtaCVSS 6,8İstismar yokEPSS %20twiki · twiki15 Eki 2014
- CVE-2012-633031İzleyin
The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows remote attackers to c
OrtaCVSS 5,0Kavram kanıtıEPSS %36twiki · twiki4 Oca 2013
- CVE-2006-381931İzleyin
Eval injection vulnerability in the configure script in TWiki 4.0.0 through 4.0.4 allows remote attackers to execute arbitrary Perl code via
YüksekCVSS 7,5Kavram kanıtıEPSS %4twiki · twiki26 Tem 2006
- CVE-2005-051631İzleyin
The ImageGalleryPlugin (ImageGalleryPlugin.pm) in Twiki allows remote attackers to execute arbitrary commands via certain commands that gene
YüksekCVSS 7,5İstismar yokEPSS %2twiki · imagegalleryplugin23 Şub 2005
- CVE-2006-138631İzleyin
The (1) rdiff and (2) preview scripts in TWiki 4.0 and 4.0.1 ignore access control settings, which allows remote attackers to read restricte
YüksekCVSS 7,5İstismar yokEPSS %2twiki · twiki26 Mar 2006
- CVE-2008-319529İzleyin
Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide is skipped, allows r
OrtaCVSS 6,8Kavram kanıtıEPSS %8twiki · twiki18 Eyl 2008
- CVE-2009-489827İzleyin
Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.2 allows remote attackers to hijack the authentication of arbitrary user
OrtaCVSS 6,8İstismar yokEPSS %1twiki · twiki7 Eyl 2010
- CVE-2008-499827İzleyin
postinst in twiki 4.1.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/twiki temporary file.
OrtaCVSS 6,9İstismar yokEPSS %0twiki · twiki7 Kas 2008
- CVE-2018-2021224İzleyin
bin/statistics in TWiki 6.0.2 allows cross-site scripting (XSS) via the webs parameter.
OrtaCVSS 6,1İstismar yokEPSS %2twiki · twiki21 Mar 2019
- CVE-2009-133924İzleyin
Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.1 allows remote authenticated users to hijack the authentication of arbi
OrtaCVSS 6,0İstismar yokEPSS %1twiki · twiki30 Nis 2009
- CVE-2006-429421İzleyin
Directory traversal vulnerability in viewfile in TWiki 4.0.0 through 4.0.4 allows remote attackers to read arbitrary files via a ..
OrtaCVSS 5,0Kavram kanıtıEPSS %4twiki · twiki8 Eyl 2006
- CVE-2007-519320İzleyin
The default configuration for twiki 4.1.2 on Debian GNU/Linux, and possibly other operating systems, specifies the work area directory (cfg{
OrtaCVSS 5,0İstismar yokEPSS %2debian · debian linux4 Eki 2007
- CVE-2006-294220İzleyin
TWiki 4.0.0, 4.0.1, and 4.0.2 allows remote attackers to gain Twiki administrator privileges via a TWiki.TWikiRegistration form with a modif
OrtaCVSS 5,1İstismar yokEPSS %2twiki · twiki20 Haz 2006
- CVE-2011-301019İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in TWiki before 5.1.0 allow remote attackers to inject arbitrary web script or HTML via
OrtaCVSS 4,3Kavram kanıtıEPSS %5twiki · twiki30 Eyl 2011
- CVE-2010-384118İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in lib/TWiki.pm in TWiki before 5.0.1 allow remote attackers to inject arbitrary web scr
OrtaCVSS 4,3Kavram kanıtıEPSS %3twiki · twiki18 Eki 2010
- CVE-2011-183818İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in TemplateLogin.pm in TWiki before 5.0.2 allow remote attackers to inject arbitrary web
OrtaCVSS 4,3Kavram kanıtıEPSS %3twiki · twiki20 May 2011
- CVE-2008-530418İzleyin
Cross-site scripting (XSS) vulnerability in TWiki before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via the %URLPA
OrtaCVSS 4,3Kavram kanıtıEPSS %2twiki · twiki9 Ara 2008
- CVE-2012-097918İzleyin
Cross-site scripting (XSS) vulnerability in TWiki allows remote attackers to inject arbitrary web script or HTML via the organization field
OrtaCVSS 4,3İstismar yokEPSS %2twiki · twiki2 Şub 2012