The remote web server includes a CGI script that allows for arbitrary
shell command execution.
Description :
According to its banner, the installed version of TWiki allows an
attacker, by manipulating input to the rev parameter, to execute
arbitrary shell commands on the remote host subject to the privileges
of the web server user id.