6.8
CVSSv2

CVE-2008-3195

Published: 18/09/2008 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 690
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in bin/configure in TWiki prior to 4.2.3, when a certain step in the installation guide is skipped, allows remote malicious users to read arbitrary files via a query string containing a .. (dot dot) in the image variable, and execute arbitrary files via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

twiki twiki 4.1.0

twiki twiki 4.0.5

twiki twiki

twiki twiki 4.0.4

twiki twiki 4.0.3

twiki twiki 4.1.1

twiki twiki 4.2.0

twiki twiki 4.0.0

twiki twiki 4.0

twiki twiki 4.1.2

twiki twiki 4.2.1

twiki twiki 4.0.2

twiki twiki 4.0.1

Exploits

TWiki versions 422 and below suffer from a remote code execution vulnerability ...
################################################################################################################ # # # TWiki 420 File Disclosure Vuln (configure) # # ...
#-----------webDEViL - [ w3bd3vil [at] gmail [dot] com ] -----------# #-----------TWiki Remote Code Execution <= 422--------------------# # ----------developers site: wwwtwikiorg-------------------# # ----------CVE Id(s) : CVE-2008-3195--------------------------# # twikiorg/cgi-bin/view/Codev/DownloadTWiki#4_2_3_Bugfix_ ...