TWiki 4.0, 4.0.1, and 20010901 through 20040904 allows remote authenticated users with edit rights to cause a denial of service (infinite recursion leading to CPU and memory consumption) via INCLUDE by URL statements that form a loop, such as a page that includes itself.
2006-03-26T22:02:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 4.0 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:N/A:P
8.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | twiki | twiki | 4.0 | Yes |
| Application | twiki | twiki | 4.0.1 | Yes |
| Application | twiki | twiki | 2001-09-01 | Yes |
| Application | twiki | twiki | 2001-12-01 | Yes |
| Application | twiki | twiki | 2003-02-01 | Yes |
| Application | twiki | twiki | 2004-09-01 | Yes |
| Application | twiki | twiki | 2004-09-02 | Yes |
| Application | twiki | twiki | 2004-09-03 | Yes |
| Application | twiki | twiki | 2004-09-04 | Yes |