The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary code via shell metacharacters, as demonstrated via the rev parameter to TWikiUsers.
2005-09-16T20:03:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | twiki | twiki | 2000-12-01 | Yes |
| Application | twiki | twiki | 2001-12-01 | Yes |
| Application | twiki | twiki | 2003-02-01 | Yes |
| Application | twiki | twiki | 2004-09-01 | Yes |
| Application | twiki | twiki | 2004-09-02 | Yes |