First published: Tue Jan 09 2001(Updated: )
Twig webmail system does not properly set the "vhosts" variable if it is not configured on the site, which allows remote attackers to insert arbitrary PHP (PHP3) code by specifying an alternate vhosts as an argument to the index.php3 program.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Twig | =2.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-1166 has been classified with a high severity due to the potential for remote code execution.
To fix CVE-2000-1166, ensure that the vhosts variable is properly configured in the Twig webmail system.
CVE-2000-1166 can enable remote attackers to execute arbitrary PHP code on the server.
CVE-2000-1166 specifically affects version 2.5.1 of the Twig webmail system.
The Twig webmail system is the software vulnerable to CVE-2000-1166 when not properly configured.