Skip to main content

Vendor archive

twiki CVEs

Beta · best-effort

30 CVEs tagged to vendor twiki6 Critical, 4 High, 20 Medium, 0 Low, 0 Unrated.

CVE-2014-7236

Published Feb 17, 2020

Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenableplugins parameter to do/view/M…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-1751

Published Nov 7, 2019

TWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' parameter value containing Perl backtick characters.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2005-3056

Published Nov 1, 2019

TWiki allows arbitrary shell command execution via the Include function

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-20212

Published Mar 21, 2019

bin/statistics in TWiki 6.0.2 allows cross-site scripting (XSS) via the webs parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9367

Published Dec 31, 2014

Incomplete blacklist vulnerability in the urlEncode function in lib/TWiki.pm in TWiki 6.0.0 and 6.0.1 allows remote attackers to conduct cross-site scripting (XSS) attacks via a "…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9325

Published Dec 31, 2014

Multiple cross-site scripting (XSS) vulnerabilities in TWiki 6.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) QUERYSTRING variable in lib/TWiki.pm o…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-7237

Published Oct 16, 2014

lib/TWiki/Sandbox.pm in TWiki 6.0.0 and earlier, when running on Windows, allows remote attackers to bypass intended access restrictions and upload files with restricted names via…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6330

Published Jan 4, 2013

The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows remote attackers to cause a denial of service (memory consum…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0979

Published Feb 2, 2012

Cross-site scripting (XSS) vulnerability in TWiki allows remote attackers to inject arbitrary web script or HTML via the organization field in a profile, involving (1) registratio…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3010

Published Sep 30, 2011

Multiple cross-site scripting (XSS) vulnerabilities in TWiki before 5.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the newtopic parameter in a WebCrea…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1838

Published May 20, 2011

Multiple cross-site scripting (XSS) vulnerabilities in TemplateLogin.pm in TWiki before 5.0.2 allow remote attackers to inject arbitrary web script or HTML via the origurl paramet…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3841

Published Oct 18, 2010

Multiple cross-site scripting (XSS) vulnerabilities in lib/TWiki.pm in TWiki before 5.0.1 allow remote attackers to inject arbitrary web script or HTML via (1) the rev parameter t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4898

Published Sep 7, 2010

Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.2 allows remote attackers to hijack the authentication of arbitrary users for requests that update pages, as de…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1339

Published Apr 30, 2009

Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that update pa…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5305

Published Dec 10, 2008

Eval injection vulnerability in TWiki before 4.2.4 allows remote attackers to execute arbitrary Perl code via the %SEARCH{}% variable.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5304

Published Dec 10, 2008

Cross-site scripting (XSS) vulnerability in TWiki before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via the %URLPARAM{}% variable.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4998

Published Nov 7, 2008

postinst in twiki 4.1.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/twiki temporary file. NOTE: the vendor disputes this vulnerability, stati…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3195

Published Sep 18, 2008

Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide is skipped, allows remote attackers to read arbitrary files…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5193

Published Oct 4, 2007

The default configuration for twiki 4.1.2 on Debian GNU/Linux, and possibly other operating systems, specifies the work area directory (cfg{RCS}{WorkAreaDir}) under the web docume…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0669

Published Feb 8, 2007

Unspecified vulnerability in Twiki 4.0.0 through 4.1.0 allows local users to execute arbitrary Perl code via unknown vectors related to CGI session files.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6071

Published Dec 2, 2006

TWiki 4.0.5 and earlier, when running under Apache 1.3 using ApacheLogin with sessions and "ErrorDocument 401" redirects to a valid wiki topic, does not properly handle failed log…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-4294

Published Sep 9, 2006

Directory traversal vulnerability in viewfile in TWiki 4.0.0 through 4.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3819

Published Jul 27, 2006

Eval injection vulnerability in the configure script in TWiki 4.0.0 through 4.0.4 allows remote attackers to execute arbitrary Perl code via an HTTP POST request containing a para…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3336

Published Jul 5, 2006

TWiki 01-Dec-2000 up to 4.0.3 allows remote attackers to bypass the upload filter and execute arbitrary code via filenames with double extensions such as ".php.en", ".php.1", and…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2942

Published Jun 20, 2006

TWiki 4.0.0, 4.0.1, and 4.0.2 allows remote attackers to gain Twiki administrator privileges via a TWiki.TWikiRegistration form with a modified action attribute that references th…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 30 CVEsPage 1 of 2