TWiki CGI Session Files Handling Unspecified Arbitrary Perl Code … - FrSIRT
TWiki CGI Session Files Handling Unspecified Arbitrary Perl Code … - FrSIRT
TWiki CGI Session Files Handling Unspecified Arbitrary Perl Code …FrSIRT, France - Feb 9, 2007… attacker with the ability to create files in the CGI session directory (eg “/tmp”) to execute arbitrary perl code with the privileges of the web server. …