Vulnerability Name: | CVE-2004-1037 (CCN-18062) | ||||||||
Assigned: | 2004-11-12 | ||||||||
Published: | 2004-11-12 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Fri Nov 12 2004 - 17:30:02 CST TWiki search function allows arbitrary shell command execution Source: CCN Type: BugTraq Mailing List, Tue Nov 16 2004 - 02:01:48 CST Re: [Full-Disclosure] TWiki search function allows arbitrary shell command execution Source: FULLDISC Type: UNKNOWN 20041116 Re: [Full-Disclosure] TWiki search function allows arbitrary shell command execution Source: MITRE Type: CNA CVE-2004-1037 Source: CONECTIVA Type: UNKNOWN CLA-2005:918 Source: BUGTRAQ Type: UNKNOWN 20041112 TWiki search function allows arbitrary shell command execution Source: GENTOO Type: UNKNOWN GLSA-200411-33 Source: CCN Type: TWiki Web site TWikiTM - A Web Based Collaboration Platform Source: CONFIRM Type: UNKNOWN http://twiki.org/cgi-bin/view/Codev/SecurityAlertExecuteCommandsWithSearch Source: CCN Type: CIAC Information Bulletin P-039 TWiki "Search.pm" Shell Command Injection Vulnerability Source: CIAC Type: UNKNOWN P-039 Source: CCN Type: GLSA-200411-33 TWiki: Arbitrary command execution Source: CCN Type: OSVDB ID: 11714 TWiki Search Function Arbitrary Command Execution Source: BID Type: Exploit, Patch, Vendor Advisory 11674 Source: CCN Type: BID-11674 TWiki Search Shell Metacharacter Remote Arbitrary Command Execution Vulnerability Source: XF Type: UNKNOWN twiki-search-command-execution(18062) Source: XF Type: UNKNOWN twik-search-command-execution(18062) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Denotes that component is vulnerable | ||||||||
BACK |