CVE-2006-3336: Medium severity Twiki TWiki vulnerability
TWiki 01-Dec-2000 up to 4.0.3 allows remote attackers to bypass the upload filter and execute arbitrary code via filenames with double extensions such as ".php.en", ".php.1", and other allowed extensions that are not .txt. NOTE: this is only a vulnerability when the server allows script execution in the pub directory.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3336?
CVE-2006-3336 has been classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2006-3336?
To fix CVE-2006-3336, you should upgrade to a fixed version of TWiki that addresses this vulnerability.
Which versions of TWiki are affected by CVE-2006-3336?
CVE-2006-3336 affects TWiki versions from 01-Dec-2000 up to 4.0.3.
Can CVE-2006-3336 be exploited remotely?
Yes, CVE-2006-3336 can be exploited by remote attackers to execute arbitrary code.
What types of filenames can exploit CVE-2006-3336?
Filenames with double extensions like '.php.en' or '.php.1' can exploit CVE-2006-3336 if the server allows script execution.