- EPSS 1.43%
- Published 02.12.2006 02:28:00
- Last modified 09.04.2025 00:30:58
TWiki 4.0.5 and earlier, when running under Apache 1.3 using ApacheLogin with sessions and "ErrorDocument 401" redirects to a valid wiki topic, does not properly handle failed login attempts, which allows remote attackers to read arbitrary content by...
- EPSS 6.2%
- Published 09.09.2006 00:04:00
- Last modified 03.04.2025 01:03:51
Directory traversal vulnerability in viewfile in TWiki 4.0.0 through 4.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
CVE-2006-3819
- EPSS 7.9%
- Published 27.07.2006 01:04:00
- Last modified 03.04.2025 01:03:51
Eval injection vulnerability in the configure script in TWiki 4.0.0 through 4.0.4 allows remote attackers to execute arbitrary Perl code via an HTTP POST request containing a parameter name starting with "TYPEOF".
- EPSS 1.06%
- Published 05.07.2006 20:05:00
- Last modified 03.04.2025 01:03:51
TWiki 01-Dec-2000 up to 4.0.3 allows remote attackers to bypass the upload filter and execute arbitrary code via filenames with double extensions such as ".php.en", ".php.1", and other allowed extensions that are not .txt. NOTE: this is only a vulne...
CVE-2006-2942
- EPSS 1.5%
- Published 20.06.2006 18:02:00
- Last modified 03.04.2025 01:03:51
TWiki 4.0.0, 4.0.1, and 4.0.2 allows remote attackers to gain Twiki administrator privileges via a TWiki.TWikiRegistration form with a modified action attribute that references the Sandbox web instead of the user web, which can then be used to associ...
- EPSS 0.78%
- Published 26.03.2006 22:02:00
- Last modified 03.04.2025 01:03:51
TWiki 4.0, 4.0.1, and 20010901 through 20040904 allows remote authenticated users with edit rights to cause a denial of service (infinite recursion leading to CPU and memory consumption) via INCLUDE by URL statements that form a loop, such as a page ...
CVE-2006-1386
- EPSS 1.2%
- Published 26.03.2006 22:02:00
- Last modified 03.04.2025 01:03:51
The (1) rdiff and (2) preview scripts in TWiki 4.0 and 4.0.1 ignore access control settings, which allows remote attackers to read restricted areas and access restricted content in TWiki topics.
CVE-2005-2877
- EPSS 81.67%
- Published 16.09.2005 20:03:00
- Last modified 03.04.2025 01:03:51
The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary code via shell metacharacters, as demonstrated via the rev parameter to TWikiUsers.
- EPSS 85.83%
- Published 01.03.2005 05:00:00
- Last modified 03.04.2025 01:03:51
The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string.