Page 2 of 10 results (0.009 seconds)

CVSS: 9.8EPSS: 6%CPEs: 1EXPL: 3

Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search search_key parameter. NOTE: the vendor points out that Twig itself is not a web application and states that it is the responsibility of web applications using Twig to properly wrap input to it ** EN DISPUTA ** Twig en versiones anteriores a la 2.4.4 permite Server-Side Template Injection (SSTI) mediante el parámetro de búsqueda search_key. NOTA: el fabricante señala que Twig no es una aplicación web y sostiene que es la responsabilidad de las aplicaciones web que emplean Twig envolver correctamente las entradas que se le proporcionan. • https://github.com/twigphp/Twig/blob/2.x/CHANGELOG https://github.com/twigphp/Twig/commit/eddb97148ad779f27e670e1e3f19fb323aedafeb https://github.com/twigphp/Twig/issues/2743 https://mobile.twitter.com/jameel_nabbo/status/1032593354704515072?s=20 https://www.exploit-db.com/exploits/44102 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges. • http://archives.neohapsis.com/archives/bugtraq/2001-11/0245.html http://www.iss.net/security_center/static/7619.php http://www.securityfocus.com/bid/3591 • CWE-312: Cleartext Storage of Sensitive Information •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

Vulnerability in The Web Information Gateway (TWIG) 2.7.1, possibly related to incorrect security rights and/or the generation of mailto links. • http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0005.html http://twig.screwdriver.net/file.php3?file=CHANGELOG •

CVSS: 7.5EPSS: 0%CPEs: 21EXPL: 1

TWIG 2.6.2 and earlier allows remote attackers to perform unauthorized database operations via a SQL injection attack on the id parameter. • http://archives.neohapsis.com/archives/bugtraq/2001-05/0260.html http://twig.screwdriver.net/index.php3 http://www.iss.net/security_center/static/6619.php http://www.securityfocus.com/bid/2791 •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

Twig webmail system does not properly set the "vhosts" variable if it is not configured on the site, which allows remote attackers to insert arbitrary PHP (PHP3) code by specifying an alternate vhosts as an argument to the index.php3 program. • http://archives.neohapsis.com/archives/bugtraq/2000-11/0351.html http://twig.screwdriver.net/file.php3?file=CHANGELOG http://www.securityfocus.com/bid/1998 https://exchange.xforce.ibmcloud.com/vulnerabilities/5581 •