漏洞信息详情
Twiki 主页创建 特权提升漏洞
漏洞简介
TWiki可以使远程攻击者借助含有经过修改的action属性的TWiki.TWikiRegistration表单,获得Twiki管理员权限。该属性引用Sandbox web而非用户web,随后,可用于将用户的登录名与TWikiAdminGroup会员的WikiName相结合。
漏洞公告
目前厂商已经发布了相关补丁,请到厂商的主页下载:
TWiki TWiki 4.0
TWiki Twiki Patch (diff file) for versions 4.0.0, 4.0.1, and 4.0.2
http://twiki.org/p/pub/Codev/SecurityAlertTWiki4PrivilegeElevation/CVE -2006-2942-hotfix-4.0.0-4.0.2.diff
TWiki TWiki 4.0.1
TWiki Twiki Patch (diff file) for versions 4.0.0, 4.0.1, and 4.0.2
http://twiki.org/p/pub/Codev/SecurityAlertTWiki4PrivilegeElevation/CVE -2006-2942-hotfix-4.0.0-4.0.2.diff
TWiki TWiki 4.0.2
TWiki Twiki Patch (diff file) for versions 4.0.0, 4.0.1, and 4.0.2
http://twiki.org/p/pub/Codev/SecurityAlertTWiki4PrivilegeElevation/CVE -2006-2942-hotfix-4.0.0-4.0.2.diff
参考网址
来源: BID
名称: 18506
链接:http://www.securityfocus.com/bid/18506
来源: VUPEN
名称: ADV-2006-2415
链接:http://www.frsirt.com/english/advisories/2006/2415
来源: twiki.org
链接:http://twiki.org/cgi-bin/view/Codev/SecurityAlertTWiki4PrivilegeElevation
来源: SECTRACK
名称: 1016323
链接:http://securitytracker.com/id?1016323
来源: SECUNIA
名称: 20596
链接:http://secunia.com/advisories/20596
来源: XF
名称: twiki-action-security-bypass(27336)
链接:http://xforce.iss.net/xforce/xfdb/27336
来源: OSVDB
名称: 26623
链接:http://www.osvdb.org/26623
来源: VULNWATCH
名称: 20060616 TWiki Security Advisory: Privilege elevation with crafted registration form (CVE-2006-2942)
链接:http://archives.neohapsis.com/archives/vulnwatch/2006-q2/0032.html
受影响实体
- Twiki Twiki:4.0.0<!--2000-1-1-->
- Twiki Twiki:4.0.1<!--2000-1-1-->
- Twiki Twiki:4.0.2<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...