CVE-2008-5305: Code Injection
Published Dec 10, 2008
·Updated
Eval injection vulnerability in TWiki before 4.2.4 allows remote attackers to execute arbitrary Perl code via the %SEARCH{}% variable.
Affected Software
13 affected components
Twiki TWiki<=4.2.3
Twiki TWiki=4.0.0
Twiki TWiki=4.0.1
Twiki TWiki=4.0.2
Twiki TWiki=4.0.3
Twiki TWiki=4.0.4
Twiki TWiki=4.0.5
Twiki TWiki=4.1.0
Twiki TWiki=4.1.1
Twiki TWiki=4.1.2
Twiki TWiki=4.2.0
Twiki TWiki=4.2.1
Twiki TWiki=4.2.2
Event History
Dec 10, 2008
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-5305?
CVE-2008-5305 is classified as a critical severity vulnerability allowing remote code execution.
2
How do I fix CVE-2008-5305?
To fix CVE-2008-5305, upgrade your TWiki installation to version 4.2.4 or later.
3
What kind of attack does CVE-2008-5305 enable?
CVE-2008-5305 enables remote attackers to execute arbitrary Perl code on vulnerable TWiki installations.
4
Which versions of TWiki are affected by CVE-2008-5305?
CVE-2008-5305 affects TWiki versions from 4.0.0 to 4.2.3 inclusive.
5
What is the main vector for exploitation of CVE-2008-5305?
The main vector for exploitation of CVE-2008-5305 is through the use of the %SEARCH{}% variable.