Cross-site scripting (XSS) vulnerability in TWiki before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via the %URLPARAM{}% variable.
https://exchange.xforce.ibmcloud.com/vulnerabilities/47122
http://www.vupen.com/english/advisories/2008/3381
http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2008-5304