PT-2007-6284 · Debian+1 · Debian+1
Published
2007-10-04
·
Updated
2008-11-15
·
CVE-2007-5193
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
TWiki version 4.1.2
Description
The default configuration of TWiki on Debian GNU/Linux, and possibly other operating systems, has a security issue. The work area directory is located under the web document root, which could allow remote attackers to access sensitive information if .htaccess restrictions are not in place.
Recommendations
For TWiki version 4.1.2, consider moving the work area directory outside of the web document root or applying .htaccess restrictions to limit access to sensitive information. As a temporary workaround, restrict access to the
cfg{RCS}{WorkAreaDir} directory to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Twiki