CVE-2005-3056
CRITICALTWiki - Remote Code Execution via Include Function
Title source: llmDescription
TWiki allows arbitrary shell command execution via the Include function
References (3)
Core 3
Core References
Third Party Advisory x_refsource_misc
https://security-tracker.debian.org/tracker/CVE-2005-3056
Patch, Vendor Advisory x_refsource_confirm
https://twiki.org/cgi-bin/view/Codev/SecurityAlertExecuteCommandsWithInclude
Mailing List, Third Party Advisory vendor-advisory
x_refsource_debian
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=330733
Scores
CVSS v3
9.8
EPSS
0.0348
EPSS Percentile
87.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-74
Status
published
Products (1)
twiki/twiki
20040902-3
Published
Nov 01, 2019
Tracked Since
Feb 18, 2026