CVE-2006-3819: High severity Twiki TWiki vulnerability
Published Jul 27, 2006
·Updated
Eval injection vulnerability in the configure script in TWiki 4.0.0 through 4.0.4 allows remote attackers to execute arbitrary Perl code via an HTTP POST request containing a parameter name starting with "TYPEOF".
Affected Software
6 affected components
Twiki TWiki=4.0
Twiki TWiki=4.0.0
Twiki TWiki=4.0.1
Twiki TWiki=4.0.2
Twiki TWiki=4.0.3
Twiki TWiki=4.0.4
Remediation
Event History
Jul 27, 2006
CVE Published
01:04 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-3819?
CVE-2006-3819 is considered a critical vulnerability due to its ability to allow remote code execution.
2
How do I fix CVE-2006-3819?
To mitigate CVE-2006-3819, upgrade to TWiki version 4.0.5 or later, where the vulnerability is patched.
3
What are the affected versions in CVE-2006-3819?
CVE-2006-3819 affects TWiki versions 4.0.0 through 4.0.4.
4
Who can exploit CVE-2006-3819?
Any remote attacker with access to send an HTTP POST request can exploit CVE-2006-3819.
5
What type of vulnerability is CVE-2006-3819?
CVE-2006-3819 is an eval injection vulnerability that allows execution of arbitrary Perl code.