5
CVSSv2

CVE-2006-4294

Published: 09/09/2006 Updated: 08/03/2011
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in viewfile in TWiki 4.0.0 up to and including 4.0.4 allows remote malicious users to read arbitrary files via a .. (dot dot) in the filename parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

twiki twiki 4.0.1

twiki twiki 4.0.2

twiki twiki 4.0.3

twiki twiki 4.0.4

twiki twiki 4.0.0

Exploits

source: wwwsecurityfocuscom/bid/19907/info Twiki is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application Information obtained may aid in further ...