Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

TWiki TWikiUsers Remote Arbitrary Command Execution Vulnerability

A remote command execution vulnerability affects the application.

The revision control function of the TWikiUsers script uses the backtick shell metacharacter to construct a command line. An attacker may use a specially crafted URI to execute arbitrary commands through the shell.

This attack would occur in the context of the vulnerable application and can facilitate unauthorized remote access.







 

Privacy Statement
Copyright 2008, SecurityFocus