CVE-2000-1166
Twig webmail system does not properly set the "vhosts" variable if it is not configured on the site, which allows remote attackers to insert arbitrary PHP (PHP3) code by specifying an alternate vhosts as an argument to the index.php3 program.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.63%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Twig webmail system does not properly set the "vhosts" variable if it is not configured on the site, which allows remote attackers to insert arbitrary PHP (PHP3) code by specifying an alternate vhosts as an argument to the index.php3 program.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.63% probability · 75th percentile
- CISA KEV
- Not listed
- Affected
- twig development team/twig
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2000-11/0351.htmlVendor Advisory
- http://twig.screwdriver.net/file.php3?file=CHANGELOG
- http://www.securityfocus.com/bid/1998Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5581
- http://archives.neohapsis.com/archives/bugtraq/2000-11/0351.htmlVendor Advisory
- http://twig.screwdriver.net/file.php3?file=CHANGELOG
- http://www.securityfocus.com/bid/1998Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5581
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.