Vulnerability Details CVE-2006-1387
TWiki 4.0, 4.0.1, and 20010901 through 20040904 allows remote authenticated users with edit rights to cause a denial of service (infinite recursion leading to CPU and memory consumption) via INCLUDE by URL statements that form a loop, such as a page that includes itself.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 72.8%
CVSS Severity
CVSS v2 Score 4.0
Products affected by CVE-2006-1387
-
cpe:2.3:a:twiki:twiki:2001-09-01
-
cpe:2.3:a:twiki:twiki:2001-12-01
-
cpe:2.3:a:twiki:twiki:2003-02-01
-
cpe:2.3:a:twiki:twiki:2004-09-01
-
cpe:2.3:a:twiki:twiki:2004-09-02
-
cpe:2.3:a:twiki:twiki:2004-09-03
-
cpe:2.3:a:twiki:twiki:2004-09-04
-
cpe:2.3:a:twiki:twiki:4.0
-
cpe:2.3:a:twiki:twiki:4.0.1