TWiki revision control shell command injection
Added: 04/06/2006CVE: CVE-2005-2877
BID: 14834
OSVDB: 19403
Background
TWiki is a web-based collaboration platform written in PERL.Problem
The revision control function in TWiki does not sufficiently check the rev parameter before using it in a shell command call. This allows remote attackers to execute arbitrary commands using a rev parameter containing shell metacharacters.Resolution
Apply the patch referenced in CIAC Bulletin P-307.References
http://archives.neohapsis.com/archives/bugtraq/2005-09/0154.htmlBack to exploit index