Lucene search

K
freebsdFreeBSDB4AF3EDE-36E9-11D9-A9E7-0001020EED82
HistoryNov 12, 2004 - 12:00 a.m.

twiki -- arbitrary shell command execution

2004-11-1200:00:00
vuxml.freebsd.org
15

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.914

Percentile

98.9%

Hans Ulrich Niedermann reports:

The TWiki search function uses a user supplied search
string to compose a command line executed by the Perl
backtick (``) operator.
The search string is not checked properly for shell
metacharacters and is thus vulnerable to search string
containing quotes and shell commands.
IMPACT: An attacker is able to execute arbitrary shell
commands with the privileges of the TWiki process.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchtwiki< 20040902UNKNOWN

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.914

Percentile

98.9%