CVE-2005-2877: High severity Twiki TWiki vulnerability
Published Sep 16, 2005
·Updated
The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary code via shell metacharacters, as demonstrated via the rev parameter to TWikiUsers.
Affected Software
5 affected components
Twiki TWiki=2000-12-01
Twiki TWiki=2001-12-01
Twiki TWiki=2003-02-01
Twiki TWiki=2004-09-01
Twiki TWiki=2004-09-02
Remediation
Patch Available
Patch Available
Event History
Sep 16, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2877?
CVE-2005-2877 has a critical severity rating due to the potential for remote code execution.
2
How do I fix CVE-2005-2877?
To fix CVE-2005-2877, upgrade to a version of TWiki that is post-September 2004 release.
3
What are the affected versions in CVE-2005-2877?
CVE-2005-2877 affects TWiki versions up to and including 02-Sep-2004.
4
How does CVE-2005-2877 allow code execution?
CVE-2005-2877 allows code execution through improper handling of shell metacharacters in the rev parameter.
5
Who can exploit CVE-2005-2877?
CVE-2005-2877 can be exploited by remote attackers without authentication.