CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
42501 | CVE-2009-5066 | Candidate | twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local users to read the credentials by listing the process and its arguments. | Assigned (20110405) | None (candidate not yet proposed) | View | |
4152 | CVE-2001-1348 | Candidate | TWIG 2.6.2 and earlier allows remote attackers to perform unauthorized database operations via a SQL injection attack on the id parameter. | Proposed (20020502) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall | Green> Even if vague, there is acknowledgement. | View |
2733 | CVE-2000-1166 | Entry | Twig webmail system does not properly set the "vhosts" variable if it is not configured on the site, which allows remote attackers to insert arbitrary PHP (PHP3) code by specifying an alternate vhosts as an argument to the index.php3 program. | View | |||
19440 | CVE-2006-3336 | Candidate | TWiki 01-Dec-2000 up to 4.0.3 allows remote attackers to bypass the upload filter and execute arbitrary code via filenames with double extensions such as ".php.en", ".php.1", and other allowed extensions that are not .txt. NOTE: this is only a vulnerability when the server allows script execution in the pub directory. | Assigned (20060702) | None (candidate not yet proposed) | View | |
17491 | CVE-2006-1387 | Candidate | TWiki 4.0, 4.0.1, and 20010901 through 20040904 allows remote authenticated users with edit rights to cause a denial of service (infinite recursion leading to CPU and memory consumption) via INCLUDE by URL statements that form a loop, such as a page that includes itself. | Assigned (20060324) | None (candidate not yet proposed) | View |
Page 18592 of 20943, showing 5 records out of 104715 total, starting on record 92956, ending on 92960