Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2011-3010

Disclosure Date: September 30, 2011 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in TWiki before 5.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the newtopic parameter in a WebCreateNewTopic action, related to the TWiki.WebCreateNewTopicTemplate topic; or (2) the query string to SlideShow.pm in the SlideShowPlugin.
0
Attacker Value
Unknown

CVE-2011-1838

Disclosure Date: May 20, 2011 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in TemplateLogin.pm in TWiki before 5.0.2 allow remote attackers to inject arbitrary web script or HTML via the origurl parameter to a (1) view script or (2) login script.
0
Attacker Value
Unknown

CVE-2010-3841

Disclosure Date: October 18, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in lib/TWiki.pm in TWiki before 5.0.1 allow remote attackers to inject arbitrary web script or HTML via (1) the rev parameter to the view script or (2) the query string to the login script.
0
Attacker Value
Unknown

CVE-2009-4898

Disclosure Date: September 07, 2010 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.2 allows remote attackers to hijack the authentication of arbitrary users for requests that update pages, as demonstrated by a URL for a save script in the ACTION attribute of a FORM element, in conjunction with a call to the submit method in the onload attribute of a BODY element. NOTE: this issue exists because of an insufficient fix for CVE-2009-1339.
0
Attacker Value
Unknown

CVE-2009-1339

Disclosure Date: April 30, 2009 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that update pages, as demonstrated by a URL for a save script in the SRC attribute of an IMG element, a related issue to CVE-2009-1434.
0
Attacker Value
Unknown

CVE-2008-5304

Disclosure Date: December 10, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in TWiki before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via the %URLPARAM{}% variable.
0
Attacker Value
Unknown

CVE-2008-5305

Disclosure Date: December 10, 2008 (last updated October 04, 2023)
Eval injection vulnerability in TWiki before 4.2.4 allows remote attackers to execute arbitrary Perl code via the %SEARCH{}% variable.
0
Attacker Value
Unknown

CVE-2008-4998

Disclosure Date: November 07, 2008 (last updated November 08, 2023)
postinst in twiki 4.1.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/twiki temporary file. NOTE: the vendor disputes this vulnerability, stating "this bug is invalid.
0
Attacker Value
Unknown

CVE-2008-3195

Disclosure Date: September 18, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide is skipped, allows remote attackers to read arbitrary files via a query string containing a .. (dot dot) in the image variable, and execute arbitrary files via unspecified vectors.
0
Attacker Value
Unknown

CVE-2007-5193

Disclosure Date: October 04, 2007 (last updated October 04, 2023)
The default configuration for twiki 4.1.2 on Debian GNU/Linux, and possibly other operating systems, specifies the work area directory (cfg{RCS}{WorkAreaDir}) under the web document root, which might allow remote attackers to obtain sensitive information when .htaccess restrictions are not applied.
0