发布时间 :2006-03-26 17:02:00
修订时间 :2017-07-19 21:30:33

[原文]The (1) rdiff and (2) preview scripts in TWiki 4.0 and 4.0.1 ignore access control settings, which allows remote attackers to read restricted areas and access restricted content in TWiki topics.

[CNNVD]TWiki Rdiff和Preview脚本远程信息泄露漏洞(CNNVD-200603-420)


- CVSS (基础分值)

CVSS分值: 7.5 [严重(HIGH)]
机密性影响: [--]
完整性影响: [--]
可用性影响: [--]
攻击复杂度: [--]
攻击向量: [--]
身份认证: [--]

- CPE (受影响的平台与产品)


- OVAL (用于检测的技术细节)


- 官方数据库链接
(官方数据源) MITRE
(官方数据源) NVD
(官方数据源) CNNVD

- 其它链接及资源
(UNKNOWN)  BID  17268
(UNKNOWN)  VUPEN  ADV-2006-1116
(UNKNOWN)  XF  twiki-restricted-content-access(25444)

- 漏洞信息

TWiki Rdiff和Preview脚本远程信息泄露漏洞
高危 输入验证
2006-03-26 00:00:00 2006-03-27 00:00:00

- 公告与补丁


- 漏洞信息

TWiki rdiff Script Restricted Content Access

- 漏洞描述

Unknown or Incomplete

- 时间线

2006-03-21 Unknow
Unknow Unknow

- 解决方案

Unknown or Incomplete

- 相关参考

- 漏洞作者

Unknown or Incomplete

- 漏洞信息

TWiki Remote Information Disclosure Vulnerability
Input Validation Error 17268
Yes No
2006-03-27 12:00:00 2006-03-28 08:13:00
Kenneth Lavrsen, Sergej Zagursky and Steffen Poulsen are credited with the discovery of this vulnerability.

- 受影响的程序版本

TWiki TWiki 4.0.1
TWiki TWiki 20040903
TWiki TWiki 20040902
TWiki TWiki 20040901
TWiki TWiki 20030201
TWiki TWiki 01-Feb-2003
TWiki TWiki 01-Dec-2001
TWiki TWiki 01-Dec-2000
TWiki TWiki 0

- 漏洞讨论

TWiki is prone to an information-disclosure vulnerability. The application fails to properly sanitize user-supplied input.

Attackers may gain access to arbitrary, restricted content files with the privileges of the hosting webserver. This can aid in further attacks.

- 漏洞利用

This issue can be exploited through use of a web client.

- 解决方案

The vendor has released a hotfix. Symantec has not tested the integrity or effectiveness of the hotfix.

Hotfix for rdiff script:

In file twiki/lib/TWiki/UI/, find sub diff. 10 lines lower in the file you will find the following line:

TWiki::UI::checkTopicExists( $session, $webName, $topic, 'diff' );

Add the following line immediately after it:

TWiki::UI::checkAccess( $session, $webName, $topic, 'view', $session->{user} );

CVE-2006-1386_UI_RDiff_pm.diff: Patch for twiki/lib/TWiki/UI/, TWiki 4.0.1 (See HowToApplyPatch)

Hotfix for preview script:

In file twiki/lib/TWiki/UI/ find the following lines:

if( $topicExists ) {
( $prevMeta, $prevText ) =
$store->readTopic( undef, $webName, $topic, undef );
if( $prevMeta ) {
foreach my $k ( keys %$prevMeta ) {

Change the call to 'readTopic' to:

$store->readTopic( $user, $webName, $topic, undef );

- 相关参考