First published: Sat Sep 09 2006(Updated: )
Directory traversal vulnerability in viewfile in TWiki 4.0.0 through 4.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TWiki | =4.0.1 | |
TWiki | =4.0.3 | |
TWiki | =4.0.4 | |
TWiki | =4.0.0 | |
TWiki | =4.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4294 is considered a high severity vulnerability due to its potential for remote file access.
To fix CVE-2006-4294, upgrade TWiki to version 4.0.5 or later, which addresses the directory traversal vulnerability.
CVE-2006-4294 affects TWiki versions 4.0.0 through 4.0.4.
CVE-2006-4294 is a directory traversal vulnerability that allows unauthorized file access.
Yes, CVE-2006-4294 can be exploited remotely by attackers to read arbitrary files on the server.