Back to search

CVE-2000-1166

HIGH
7.5NVD

Twig webmail system does not properly set the "vhosts" variable if it is not configured on the site, which allows remote attackers to insert arbitrary PHP (PHP3) code by specifying an alternate vhosts as an argument to the index.php3 program.

CVSS v2.0 Score

7.5
/ 10.0
HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P

Information

Published
9 janv. 2001
Updated
16 avr. 2026
Status
Modified
Source
cve@mitre.org

Affected products

twig development team twig
Versions : 2.5.1

Weaknesses (CWE)

NVD-CWE-Other

Monitor your products

Get automatic alerts for every new CVE affecting your equipment.

Enable monitoring