CVE-2014-7236

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
17/02/2020
Last modified:
20/02/2020

Description

Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenableplugins parameter to do/view/Main/WebHome.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:twiki:twiki:*:*:*:*:*:*:*:* 4.0 (including) 4.0.5 (including)
cpe:2.3:a:twiki:twiki:*:*:*:*:*:*:*:* 4.1 (including) 4.1.2 (including)
cpe:2.3:a:twiki:twiki:*:*:*:*:*:*:*:* 4.2 (including) 4.2.4 (including)
cpe:2.3:a:twiki:twiki:*:*:*:*:*:*:*:* 4.3 (including) 4.3.2 (including)
cpe:2.3:a:twiki:twiki:*:*:*:*:*:*:*:* 5.0 (including) 5.0.2 (including)
cpe:2.3:a:twiki:twiki:*:*:*:*:*:*:*:* 5.1.0 (including) 5.1.4 (including)
cpe:2.3:a:twiki:twiki:6.0:*:*:*:*:*:*:*