Search:     Advanced search
server monitoring

TWiki INCLUDE Function Command Execution Vulnerability

Article ID: 20068
Last updated: 27 Jan, 2009
Views: 464
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

TWiki INCLUDE Function Command Execution Vulnerability

This script is Copyright (C) 2005-2008 Tenable Network Security

FamilyGain a shell remotely
Plugin ID20068
Bugtraq ID14960
CVE IDCVE-2005-3056

Description:

Synopsis :

The remote web server includes a CGI script that allows for arbitrary
shell command execution.

Description :

According to its banner, the installed version of TWiki allows an
attacker, by manipulating input to the rev parameter, to execute
arbitrary shell commands on the remote host subject to the privileges
of the web server user id.

See also :

http://twiki.org/cgi-bin/view/Codev/SecurityAlertExecuteCommandsWithInclude

Solution :

Apply the appropriate hotfix listed in the vendor advisory.

Risk factor :

Medium / CVSS Base Score : 6.5
(CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P)
This article was:   Helpful | Not Helpful
Prev   Next
Kerio MailServer < 6.0.3     OpenSSH 2.5.x - 2.9.x adv.option