Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Twiki CRITICAL 9.1
CVE-2014-7236EPSS 56%

Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenable…

Fix: after 5.1.4
Fix from $2,300 2020-02-17
Twiki CRITICAL 9.8
CVE-2013-1751

TWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' parameter value containing Perl ba…

Fix: 5.1.4+
Fix from $2,300 2019-11-07
Twiki CRITICAL 9.8
CVE-2005-3056

TWiki allows arbitrary shell command execution via the Include function

Patch available
Fix from $2,300 2019-11-01
Twiki MEDIUM 6.1
CVE-2018-20212

bin/statistics in TWiki 6.0.2 allows cross-site scripting (XSS) via the webs parameter.

No fix yet
Fix from $1,600 2019-03-21
Twiki MEDIUM 6.8
CVE-2014-7237EPSS 20%

lib/TWiki/Sandbox.pm in TWiki 6.0.0 and earlier, when running on Windows, allows remote attackers to bypass intended access restrictions and upload f…

Fix: after 6.0.0
Fix from $1,600 2014-10-16
Twiki MEDIUM 5.0
CVE-2012-6330EPSS 36%

The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows remote attackers to cause a de…

Fix: after 5.1.2
Fix from $1,600 2013-01-04
Twiki MEDIUM 6.8
CVE-2009-4898

Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.2 allows remote attackers to hijack the authentication of arbitrary users for req…

Fix: after 4.3.1
Fix from $1,600 2010-09-07
Twiki MEDIUM 6.0
CVE-2009-1339

Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.1 allows remote authenticated users to hijack the authentication of arbitrary use…

Fix: after 4.3.0
Fix from $1,600 2009-04-30
Twiki HIGH 10.0
CVE-2008-5305

Eval injection vulnerability in TWiki before 4.2.4 allows remote attackers to execute arbitrary Perl code via the %SEARCH{}% variable.

Fix: after 4.2.3
Fix from $1,950 2008-12-10
Twiki MEDIUM 6.9
CVE-2008-4998

postinst in twiki 4.1.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/twiki temporary file. NOTE: the vendor disp…

Mitigation only
Fix from $1,600 2008-11-07
Twiki MEDIUM 6.8
CVE-2008-3195EPSS 8%

Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide is skipped, allows remote att…

Fix: after 4.2.2
Fix from $1,600 2008-09-18
Twiki MEDIUM 5.0
CVE-2007-5193

The default configuration for twiki 4.1.2 on Debian GNU/Linux, and possibly other operating systems, specifies the work area directory (cfg{RCS}{Work…

Mitigation only
Fix from $1,600 2007-10-04
Twiki HIGH 9.0
CVE-2006-6071

TWiki 4.0.5 and earlier, when running under Apache 1.3 using ApacheLogin with sessions and "ErrorDocument 401" redirects to a valid wiki topic, does …

Fix: after 4.0.5
Fix from $1,950 2006-12-02
Twiki MEDIUM 5.0
CVE-2006-4294

Directory traversal vulnerability in viewfile in TWiki 4.0.0 through 4.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the …

Patch available
Fix from $1,600 2006-09-09
Twiki HIGH 7.5
CVE-2006-3819

Eval injection vulnerability in the configure script in TWiki 4.0.0 through 4.0.4 allows remote attackers to execute arbitrary Perl code via an HTTP …

Patch available
Fix from $1,950 2006-07-27
Twiki MEDIUM 5.1
CVE-2006-2942

TWiki 4.0.0, 4.0.1, and 4.0.2 allows remote attackers to gain Twiki administrator privileges via a TWiki.TWikiRegistration form with a modified actio…

Patch available
Fix from $1,600 2006-06-20
Twiki HIGH 7.5
CVE-2006-1386

The (1) rdiff and (2) preview scripts in TWiki 4.0 and 4.0.1 ignore access control settings, which allows remote attackers to read restricted areas a…

Mitigation only
Fix from $1,950 2006-03-26
Twiki HIGH 7.5
CVE-2005-2877EPSS 71%

The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary code via shell metacharacters, …

Patch available
Fix from $1,950 2005-09-16
Imagegalleryplugin HIGH 7.5
CVE-2005-0516

The ImageGalleryPlugin (ImageGalleryPlugin.pm) in Twiki allows remote attackers to execute arbitrary commands via certain commands that generate thum…

Patch available
Fix from $1,950 2005-02-23