Back to search
CVE-2014-9367
Published: Dec 31, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
Incomplete blacklist vulnerability in the urlEncode function in lib/TWiki.pm in TWiki 6.0.0 and 6.0.1 allows remote attackers to conduct cross-site scripting (XSS) attacks via a "'" (single quote) in the scope parameter to do/view/TWiki/WebSearch.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20141219 TWiki Security Alert CVE-2014-9367: XSS Vulnerability with Scope and Other URL Parameters of WebSearch
mailing-list
x_refsource_FULLDISC
http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2014-9367
x_refsource_CONFIRM
1031400
vdb-entry
x_refsource_SECTRACK
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now