Return to CVE list

CVE-2006-4294

5.0
Medium

CVE-2006-4294

cve@mitre.org
Deferred

Description

Directory traversal vulnerability in viewfile in TWiki 4.0.0 through 4.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

Exploits

284952006-09-07webappsPHP

TWiki 4.0.x - 'Viewfile' Directory Traversal

By Peter Thoeny