PT-2007-6284 · Debian+1 · Debian+1
Publicado
2007-10-04
·
Atualizado
2008-11-15
·
CVE-2007-5193
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
TWiki version 4.1.2
Description
The default configuration of TWiki on Debian GNU/Linux, and possibly other operating systems, has a security issue. The work area directory is located under the web document root, which could allow remote attackers to access sensitive information if .htaccess restrictions are not in place.
Recommendations
For TWiki version 4.1.2, consider moving the work area directory outside of the web document root or applying .htaccess restrictions to limit access to sensitive information. As a temporary workaround, restrict access to the
cfg{RCS}{WorkAreaDir} directory to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Debian
Twiki