CVE-2013-1751: Input Validation
Published Nov 7, 2019
·Updated
TWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' parameter value containing Perl backtick characters.
Affected Software
2 affected components
debian/twiki
Twiki TWiki<5.1.4
Remediation
Event History
Nov 7, 2019
CVE Published
via MITRE·09:51 PM
Data Sourced
via MITRE·09:51 PM
Description
Frequently Asked Questions
1
What is CVE-2013-1751?
CVE-2013-1751 is a vulnerability in TWiki versions before 5.1.4 that allows remote attackers to execute arbitrary shell commands.
2
How can an attacker exploit CVE-2013-1751?
An attacker can exploit CVE-2013-1751 by sending a crafted '%MAKETEXT{}%' parameter value containing Perl backtick characters.
3
What is the severity of CVE-2013-1751?
CVE-2013-1751 has a severity rating of 9.8 (Critical).
4
Which software versions are affected by CVE-2013-1751?
TWiki versions before 5.1.4 are affected by CVE-2013-1751.
5
Are there any fixes available for CVE-2013-1751?
There are no known fixes available for CVE-2013-1751.