« Return to Thread: Bug#499534: twiki: Remote code execution vulerability.

Bug#499534: twiki: Remote code execution vulerability.

by Nico Golde-6 :: Rate this Message:

Reply (Restricted by the Administrator) | Reply to Author | View in Thread

severity 499534 important
thanks

Hi Brad,
* Brad Krane <bjkrane@...> [2008-09-19 19:18]:
> TWiki command execution vulnerability found in current version. US-CERT Vulnerability Note:
> http://www.kb.cert.org/vuls/id/362012 and TWiki Security Alert:
> http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2008-3195

Downgrading as the access to this script is limited to
localhost on Debian.

Cheers
Nico
--
Nico Golde - http://www.ngolde.de - nion@... - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.


attachment0 (204 bytes) Download Attachment

 « Return to Thread: Bug#499534: twiki: Remote code execution vulerability.