Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown
CVE-2015-7809
Disclosure Date: November 06, 2015 (last updated October 05, 2023)
The displayBlock function Template.php in Sensio Labs Twig before 1.20.0, when Sandbox mode is enabled, allows remote attackers to execute arbitrary code via the _self variable in a template.
0
Attacker Value
Unknown
CVE-2001-1537
Disclosure Date: December 31, 2001 (last updated February 22, 2025)
The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges.
0
Attacker Value
Unknown
CVE-2001-1361
Disclosure Date: July 19, 2001 (last updated February 22, 2025)
Vulnerability in The Web Information Gateway (TWIG) 2.7.1, possibly related to incorrect security rights and/or the generation of mailto links.
0
Attacker Value
Unknown
CVE-2001-1348
Disclosure Date: May 28, 2001 (last updated February 22, 2025)
TWIG 2.6.2 and earlier allows remote attackers to perform unauthorized database operations via a SQL injection attack on the id parameter.
0
Attacker Value
Unknown
CVE-2000-1166
Disclosure Date: January 09, 2001 (last updated February 22, 2025)
Twig webmail system does not properly set the "vhosts" variable if it is not configured on the site, which allows remote attackers to insert arbitrary PHP (PHP3) code by specifying an alternate vhosts as an argument to the index.php3 program.
0