CVE-2014-7236

CRITICAL

TWiki Debugenableplugins Remote Code Execution

Title source: metasploit
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2014-7236. PoCs published by Metasploit, m0nad, Netanel Rubin, h0ng10, including Metasploit module exploits/unix/http/twiki_debug_plugins.

AI-analyzed exploit summary This Metasploit module exploits a Perl eval injection vulnerability in TWiki's debug functionality, allowing remote code execution via the unsanitized 'debugenableplugins' parameter.

Description

Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenableplugins parameter to do/view/Main/WebHome.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotephp
https://www.exploit-db.com/exploits/36438

This Metasploit module exploits a Perl eval injection vulnerability in TWiki's debug functionality, allowing remote code execution via the unsanitized 'debugenableplugins' parameter.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: TWiki 4.0.x-6.0.0
No auth needed
Prerequisites: Network access to TWiki instance · Debug functionality enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 10 stars
by m0nad · poc
https://github.com/m0nad/CVE-2014-7236_Exploit

This exploit leverages a command injection vulnerability in TWiki's BackupRestorePlugin via the `debugenableplugins` parameter. It constructs a payload that executes arbitrary commands on the target system by bypassing input validation.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: TWiki (specific version not specified, but CVE-2014-7236 affects versions prior to 6.0.0)
No auth needed
Prerequisites: Target TWiki instance with BackupRestorePlugin enabled · Network access to the TWiki server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Netanel Rubin, h0ng10 · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/http/twiki_debug_plugins.rb

This Metasploit module exploits CVE-2014-7236, a remote code execution vulnerability in TWiki's debug functionality. It leverages unsanitized input in the `debugenableplugins` parameter to execute arbitrary Perl code via an eval statement.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: TWiki 4.0.x-6.0.0
No auth needed
Prerequisites: Network access to the TWiki instance · Debug functionality enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/70372
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/128623/Twiki-Perl-Code-Execution.html
Exploit, Mailing List, Third Party Advisory x_refsource_misc
http://seclists.org/fulldisclosure/2014/Oct/44
Third Party Advisory, VDB Entry x_refsource_misc
http://www.securitytracker.com/id/1030981

Scores

CVSS v3 9.1
EPSS 0.8423
EPSS Percentile 99.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-74
Status published
Products (2)
twiki/twiki 6.0
twiki/twiki 4.0 - 4.0.5
Published Feb 17, 2020
Tracked Since Feb 18, 2026