7.5
CVSSv2

CVE-2005-2877

Published: 16/09/2005 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 765
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The history (revision control) function in TWiki 02-Sep-2004 and previous versions allows remote malicious users to execute arbitrary code via shell metacharacters, as demonstrated via the rev parameter to TWikiUsers.

Vulnerable Product Search on Vulmon Subscribe to Product

twiki twiki 2004-09-01

twiki twiki 2004-09-02

twiki twiki 2000-12-01

twiki twiki 2001-12-01

twiki twiki 2003-02-01

Exploits

## # $Id: twiki_historyrb 9671 2010-07-03 06:21:31Z jduck $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' class Me ...
source: wwwsecurityfocuscom/bid/14834/info A remote command execution vulnerability affects the application The revision control function of the TWikiUsers script uses the backtick shell metacharacter to construct a command line An attacker may use a specially crafted URI to execute arbitrary commands through the shell This attack wo ...
source: wwwsecurityfocuscom/bid/14960/info A remote command execution vulnerability affects the application The revision control function of the TWikiUsers script uses the backtick shell metacharacter to construct a command line An attacker may use a specially crafted URI to execute arbitrary commands through the shell This attack wo ...