Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2011-3010

Disclosure Date: September 30, 2011 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in TWiki before 5.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the newtopic parameter in a WebCreateNewTopic action, related to the TWiki.WebCreateNewTopicTemplate topic; or (2) the query string to SlideShow.pm in the SlideShowPlugin.
0
Attacker Value
Unknown

CVE-2011-1838

Disclosure Date: May 20, 2011 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in TemplateLogin.pm in TWiki before 5.0.2 allow remote attackers to inject arbitrary web script or HTML via the origurl parameter to a (1) view script or (2) login script.
0
Attacker Value
Unknown

CVE-2009-4898

Disclosure Date: September 07, 2010 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.2 allows remote attackers to hijack the authentication of arbitrary users for requests that update pages, as demonstrated by a URL for a save script in the ACTION attribute of a FORM element, in conjunction with a call to the submit method in the onload attribute of a BODY element. NOTE: this issue exists because of an insufficient fix for CVE-2009-1339.
0
Attacker Value
Unknown

CVE-2009-1339

Disclosure Date: April 30, 2009 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that update pages, as demonstrated by a URL for a save script in the SRC attribute of an IMG element, a related issue to CVE-2009-1434.
0
Attacker Value
Unknown

CVE-2008-5304

Disclosure Date: December 10, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in TWiki before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via the %URLPARAM{}% variable.
0
Attacker Value
Unknown

CVE-2008-5305

Disclosure Date: December 10, 2008 (last updated October 04, 2023)
Eval injection vulnerability in TWiki before 4.2.4 allows remote attackers to execute arbitrary Perl code via the %SEARCH{}% variable.
0
Attacker Value
Unknown

CVE-2008-3195

Disclosure Date: September 18, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide is skipped, allows remote attackers to read arbitrary files via a query string containing a .. (dot dot) in the image variable, and execute arbitrary files via unspecified vectors.
0