PT-2006-4228 · Twiki · Twiki
Tom Mcadam
·
Publicado
2006-07-05
·
Atualizado
2011-03-08
·
CVE-2006-3336
CVSS v2.0
4.0
Média
| Vetor | AV:N/AC:H/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
TWiki versions 01-Dec-2000 up to 4.0.3
Description
The issue allows remote attackers to bypass the upload filter and execute arbitrary code via filenames with double extensions. This is only a problem when the server allows script execution in the pub directory.
Recommendations
For TWiki versions 01-Dec-2000 up to 4.0.3, restrict script execution in the pub directory to prevent exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Twiki