First published: Fri Nov 19 2004(Updated: )
The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Twiki Twiki | =2003-02-01 | |
Gentoo Linux |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1037 has been assigned a medium severity level due to the potential for remote command execution by attackers.
To mitigate CVE-2004-1037, upgrade to a patched version of TWiki that addresses this vulnerability.
CVE-2004-1037 allows remote attackers to execute arbitrary commands, compromising the security and integrity of the TWiki system.
While CVE-2004-1037 specifically targets TWiki, similar vulnerabilities could potentially affect other applications that parse user input unsafely.
CVE-2004-1037 specifically affects TWiki version 2003-02-01.