Show plain JSON{"id": "CVE-2006-2942", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 5.1, "accessVector": "NETWORK", "vectorString": "AV:N/AC:H/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "HIGH", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 4.9, "obtainUserPrivilege": false, "obtainOtherPrivilege": true, "userInteractionRequired": false}]}, "published": "2006-06-20T18:02:00.000", "references": [{"url": "http://archives.neohapsis.com/archives/vulnwatch/2006-q2/0032.html", "source": "cve@mitre.org"}, {"url": "http://secunia.com/advisories/20596", "tags": ["Patch", "Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "http://securitytracker.com/id?1016323", "tags": ["Patch"], "source": "cve@mitre.org"}, {"url": "http://twiki.org/cgi-bin/view/Codev/SecurityAlertTWiki4PrivilegeElevation", "tags": ["Patch", "Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "http://www.osvdb.org/26623", "source": "cve@mitre.org"}, {"url": "http://www.securityfocus.com/bid/18506", "tags": ["Patch"], "source": "cve@mitre.org"}, {"url": "http://www.vupen.com/english/advisories/2006/2415", "source": "cve@mitre.org"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27336", "source": "cve@mitre.org"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "NVD-CWE-Other"}]}], "descriptions": [{"lang": "en", "value": "TWiki 4.0.0, 4.0.1, and 4.0.2 allows remote attackers to gain Twiki administrator privileges via a TWiki.TWikiRegistration form with a modified action attribute that references the Sandbox web instead of the user web, which can then be used to associate the user's login name with the WikiName of a member of the TWikiAdminGroup."}, {"lang": "es", "value": "TWiki 4.0.0, 4.0.1 y 4.0.2 permite a atacantes remotos obtener privielgios de administrador de Twiki a trav\u00e9s de un formulario TWiki.TWikiRegistration con un atributo de acci\u00f3n modificado que hace referencia a la Sandbox web en lugar de la user web, lo que puede ser utilizado para asociar el nombre de inicio de sesi\u00f3n de un usuario con el WikiName de un miembro de TWikiAdminGroup."}], "lastModified": "2017-07-20T01:31:54.927", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:twiki:twiki:4.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F893E121-82FA-41C8-9BA4-606E6DA01408"}, {"criteria": "cpe:2.3:a:twiki:twiki:4.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "47807C3A-8430-48E3-A7C8-C5A1FEDF84C0"}, {"criteria": "cpe:2.3:a:twiki:twiki:4.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "620356EA-F106-41DF-AADA-C1EF5A5A0829"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org", "evaluatorSolution": "Successful exploitation requires that the \"MapUserToWikiName\" setting is enabled."}