PT-2006-6716 · Apache+1 · Apache+1

George Clark

·

Published

2006-12-02

·

Updated

2017-07-20

·

CVE-2006-6071

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TWiki versions 4.0.5 and earlier
Description The issue arises when TWiki is running under Apache 1.3, using ApacheLogin with sessions, and "ErrorDocument 401" redirects to a valid wiki topic. In this setup, failed login attempts are not properly handled, allowing remote attackers to read arbitrary content. This can be achieved by cancelling out of a failed authentication with a valid username and an invalid password.
Recommendations For TWiki versions 4.0.5 and earlier, consider updating to a version that properly handles failed login attempts to prevent unauthorized access to content. As a temporary workaround, restrict access to sensitive wiki topics until a proper fix is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6071

Affected Products

Apache
Twiki