Secunia Logo
 
CVE Reference: CVE-2006-1387
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-1387

Description:
TWiki 4.0, 4.0.1, and 20010901 through 20040904 allows remote authenticated users with edit rights to cause a denial of service (infinite recursion leading to CPU and memory consumption) via INCLUDE by URL statements that form a loop, such as a page that includes itself.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/25445

SAID
  Secunia Advisory: SA19410

CONFIRM
  http://twiki.org/cgi-bin/view/Codev/SecurityAdvisoryDosAttackWithInclude

BID
  17267


Return to the previous page.