|
|
|
Vulnerability Note VU#584436TWiki vulnerable to arbitrary code execution via CGI session filesOverviewTWiki fails to protect the CGI session directory, which may allow an attacker to execute arbitrary code with the privileges of the web server.I. DescriptionTWiki is a web-based collaborative publishing environment. TWiki creates CGI session files in the global /tmp directory, which is generally world readable and writable. By creating CGI session files in this directory, an attacker may be able to execute arbitrary code.II. ImpactAn attacker with the ability to create files in the CGI session directory (usually /tmp) may be able to execute arbitrary code with the privileges of the web server.III. SolutionApply an updateThis issue is addressed in TWikiRelease04x01x01, as specified in TWiki SecurityAlert-CVE-2007-0669.
Systems Affected
References
Thanks to Peter Thoeny for reporting this vulnerability. This document was written by Will Dormann.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||