10
CVSSv2

CVE-2008-5305

Published: 10/12/2008 Updated: 03/03/2009
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Eval injection vulnerability in TWiki prior to 4.2.4 allows remote malicious users to execute arbitrary Perl code via the %SEARCH{}% variable.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

twiki twiki 4.1.0

twiki twiki 4.0.5

twiki twiki 4.2.2

twiki twiki 4.0.4

twiki twiki 4.0.3

twiki twiki 4.2.1

twiki twiki 4.2.0

twiki twiki 4.0.2

twiki twiki 4.0.1

twiki twiki 4.1.2

twiki twiki 4.1.1

twiki twiki 4.0.0

twiki twiki

Exploits

source: wwwsecurityfocuscom/bid/32668/info TWiki is prone to a vulnerability that attackers can leverage to execute arbitrary commands in the context of the application This issue occurs because the application fails to adequately sanitize user-supplied input Successful attacks can compromise the affected application and possibly the u ...