TWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' parameter value containing Perl backtick characters.
https://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2013-1751
https://security-tracker.debian.org/tracker/CVE-2013-1751
http://www.securitytracker.com/id/1028149
Source: Mitre, NVD
Published: 2019-11-07
Updated: 2019-11-08
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H