CVE Vulnerabilities

CVE-2006-2942

Published: Jun 20, 2006 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

TWiki 4.0.0, 4.0.1, and 4.0.2 allows remote attackers to gain Twiki administrator privileges via a TWiki.TWikiRegistration form with a modified action attribute that references the Sandbox web instead of the user web, which can then be used to associate the users login name with the WikiName of a member of the TWikiAdminGroup.

Affected Software

Name Vendor Start Version End Version
Twiki Twiki 4.0.0 (including) 4.0.0 (including)
Twiki Twiki 4.0.1 (including) 4.0.1 (including)
Twiki Twiki 4.0.2 (including) 4.0.2 (including)

References