PT-2006-6716 · Apache+1 · Apache+1
George Clark
·
Published
2006-12-02
·
Updated
2017-07-20
·
CVE-2006-6071
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TWiki versions 4.0.5 and earlier
Description
The issue arises when TWiki is running under Apache 1.3, using ApacheLogin with sessions, and "ErrorDocument 401" redirects to a valid wiki topic. In this setup, failed login attempts are not properly handled, allowing remote attackers to read arbitrary content. This can be achieved by cancelling out of a failed authentication with a valid username and an invalid password.
Recommendations
For TWiki versions 4.0.5 and earlier, consider updating to a version that properly handles failed login attempts to prevent unauthorized access to content. As a temporary workaround, restrict access to sensitive wiki topics until a proper fix is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache
Twiki