← Vulnerability feed

Vulnerability record · CVE-2005-2877 · published 16 September 2005

CVE-2005-2877: TWiki history function command injection via rev parameter

Twiki · Twiki

The revision control (history) function in TWiki 02-Sep-2004 and earlier fails to sanitize shell metacharacters, allowing remote attackers to inject commands. Because the flaw is reachable over the network without authentication, it exposes wiki servers to arbitrary code execution.

7.5 CVSS 2.0 High EPSS 71% · top 0.6%
7.5CVSS 2.0 base score
71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary code via shell metacharacters, as demonstrated via the rev parameter to TWikiUsers.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote unauthenticated command execution with public exploit code and very high EPSS, though the product is old and the record lacks modern scoring detail.

What it is

The revision control (history) function in TWiki 02-Sep-2004 and earlier fails to sanitize shell metacharacters, allowing remote attackers to inject commands. Because the flaw is reachable over the network without authentication, it exposes wiki servers to arbitrary code execution.

Impact

An attacker can execute arbitrary commands with the privileges of the web server user, leading to full compromise of the TWiki host and any data it can reach.

Attack surface

Reached remotely over the network through the rev parameter to TWikiUsers; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.

Exploitation

No CISA KEV listing, but EPSS is 0.70903 (99.4th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit code exists.

What to do

  • Upgrade TWiki to a version later than 02-Sep-2004 that includes the vendor patch referenced in the TWiki security alert.
  • If immediate upgrade is not possible, restrict network access to the TWiki history/TWikiUsers functionality to trusted users only.
  • Run the web server process under a low-privilege account with no shell access to limit command execution impact.
  • Review and harden any wrapper scripts that pass user-supplied parameters to the shell, avoiding shell invocation where possible.

Detection

  • Monitor web server logs for requests to TWikiUsers with rev parameters containing shell metacharacters such as ;, |, `, $(), or &&.
  • Alert on unexpected child processes spawned by the web server user (for example shell or command interpreters).
  • Audit outbound network connections and file writes originating from the TWiki process for signs of post-exploitation activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-2877 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-5305Twiki code injection vulnerabilityEval injection vulnerability in TWiki before 4.2.4 allows remote attackers to execute arbitrary Perl code via the %SEARCH{}% variable.EPSS 4.6%10.0CVE-2004-1037TWiki search function allows remote command executionThe search function in TWiki 20030201 passes user-supplied search strings to a shell without sanitizing shell metacharacters, allowing command inject…EPSS 62%analysed9.8CVE-2013-1751Twiki improper input validation vulnerabilityTWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' parameter value containing Perl ba…EPSS 4.9%9.8CVE-2005-3056Twiki injection vulnerabilityTWiki allows arbitrary shell command execution via the Include functionEPSS 3.5%9.1CVE-2014-7236TWiki Plugins.pm eval injection allows remote Perl code executionTWiki before 6.0.1 contains an eval injection flaw in lib/TWiki/Plugins.pm. The debugenableplugins parameter passed to do/view/Main/WebHome is evalua…EPSS 56%analysed9.0CVE-2006-6071Twiki vulnerabilityTWiki 4.0.5 and earlier, when running under Apache 1.3 using ApacheLogin with sessions and "ErrorDocument 401" redirects to a valid wiki topic, does …EPSS 2.2%7.5CVE-2006-3819Twiki vulnerabilityEval injection vulnerability in the configure script in TWiki 4.0.0 through 4.0.4 allows remote attackers to execute arbitrary Perl code via an HTTP …EPSS 4.1%7.5CVE-2006-1386Twiki vulnerabilityThe (1) rdiff and (2) preview scripts in TWiki 4.0 and 4.0.1 ignore access control settings, which allows remote attackers to read restricted areas a…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2005-2877), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.