The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary code via shell metacharacters, as demonstrated via the rev parameter to TWikiUsers.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Twiki | Twiki | 2000-12-01 (including) | 2000-12-01 (including) |
Twiki | Twiki | 2001-12-01 (including) | 2001-12-01 (including) |
Twiki | Twiki | 2003-02-01 (including) | 2003-02-01 (including) |
Twiki | Twiki | 2004-09-01 (including) | 2004-09-01 (including) |
Twiki | Twiki | 2004-09-02 (including) | 2004-09-02 (including) |
Twiki | Ubuntu | devel | * |