The default configuration for twiki 4.1.2 on Debian GNU/Linux, and possibly other operating systems, specifies the work area directory (cfg{RCS}{WorkAreaDir}) under the web document root, which might allow remote attackers to obtain sensitive information when .htaccess restrictions are not applied.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Debian_linux | Debian | * | * |
Twiki | Ubuntu | dapper | * |
Twiki | Ubuntu | edgy | * |
Twiki | Ubuntu | feisty | * |
Twiki | Ubuntu | gutsy | * |
Twiki | Ubuntu | hardy | * |
Twiki | Ubuntu | intrepid | * |
Twiki | Ubuntu | jaunty | * |
Twiki | Ubuntu | karmic | * |