CVE-2006-1387

TWiki 4.0, 4.0.1, and 20010901 through 20040904 allows remote authenticated users with edit rights to cause a denial of service (infinite recursion leading to CPU and memory consumption) via INCLUDE by URL statements that form a loop, such as a page that includes itself.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:twiki:twiki:4.0:*:*:*:*:*:*:*
cpe:2.3:a:twiki:twiki:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:twiki:twiki:2001-09-01:*:*:*:*:*:*:*
cpe:2.3:a:twiki:twiki:2001-12-01:*:*:*:*:*:*:*
cpe:2.3:a:twiki:twiki:2003-02-01:*:*:*:*:*:*:*
cpe:2.3:a:twiki:twiki:2004-09-01:*:*:*:*:*:*:*
cpe:2.3:a:twiki:twiki:2004-09-02:*:*:*:*:*:*:*
cpe:2.3:a:twiki:twiki:2004-09-03:*:*:*:*:*:*:*
cpe:2.3:a:twiki:twiki:2004-09-04:*:*:*:*:*:*:*

History

21 Nov 2024, 00:08

Type Values Removed Values Added
References () http://secunia.com/advisories/19410 - () http://secunia.com/advisories/19410 -
References () http://twiki.org/cgi-bin/view/Codev/SecurityAdvisoryDosAttackWithInclude - () http://twiki.org/cgi-bin/view/Codev/SecurityAdvisoryDosAttackWithInclude -
References () http://www.securityfocus.com/bid/17267 - () http://www.securityfocus.com/bid/17267 -
References () http://www.vupen.com/english/advisories/2006/1116 - () http://www.vupen.com/english/advisories/2006/1116 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/25445 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/25445 -

Information

Published : 2006-03-26 22:02

Updated : 2024-11-21 00:08


NVD link : CVE-2006-1387

Mitre link : CVE-2006-1387

CVE.ORG link : CVE-2006-1387


JSON object : View

Products Affected

twiki

  • twiki