First published: Fri Sep 16 2005(Updated: )
The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary code via shell metacharacters, as demonstrated via the rev parameter to TWikiUsers.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Twiki Twiki | =2000-12-01 | |
Twiki Twiki | =2004-09-02 | |
Twiki Twiki | =2003-02-01 | |
Twiki Twiki | =2001-12-01 | |
Twiki Twiki | =2004-09-01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2877 has a critical severity rating due to the potential for remote code execution.
To fix CVE-2005-2877, upgrade to a version of TWiki that is post-September 2004 release.
CVE-2005-2877 affects TWiki versions up to and including 02-Sep-2004.
CVE-2005-2877 allows code execution through improper handling of shell metacharacters in the rev parameter.
CVE-2005-2877 can be exploited by remote attackers without authentication.