CVE Vulnerabilities

CVE-2014-7236

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Published: Feb 17, 2020 | Modified: Feb 20, 2020
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenableplugins parameter to do/view/Main/WebHome.

Weakness

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Affected Software

Name Vendor Start Version End Version
Twiki Twiki 4.0 (including) 4.0.5 (including)
Twiki Twiki 4.1 (including) 4.1.2 (including)
Twiki Twiki 4.2 (including) 4.2.4 (including)
Twiki Twiki 4.3 (including) 4.3.2 (including)
Twiki Twiki 5.0 (including) 5.0.2 (including)
Twiki Twiki 5.1.0 (including) 5.1.4 (including)
Twiki Twiki 6.0 (including) 6.0 (including)

Potential Mitigations

References