CVE Vulnerabilities

CVE-2006-6071

Published: Dec 02, 2006 | Modified: Jul 20, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

TWiki 4.0.5 and earlier, when running under Apache 1.3 using ApacheLogin with sessions and ErrorDocument 401 redirects to a valid wiki topic, does not properly handle failed login attempts, which allows remote attackers to read arbitrary content by cancelling out of a failed authentication with a valid username and invalid password.

Affected Software

Name Vendor Start Version End Version
Twiki Twiki * 4.0.5 (including)
Twiki Ubuntu dapper *
Twiki Ubuntu edgy *
Twiki Ubuntu feisty *
Twiki Ubuntu gutsy *
Twiki Ubuntu hardy *
Twiki Ubuntu intrepid *
Twiki Ubuntu jaunty *
Twiki Ubuntu karmic *

References