CVE-2006-6071
Last modified
CVE-2006-6071 is a vulnerability of currently unknown severity. TWiki 4.0.5 and earlier, when running under Apache 1.3 using ApacheLogin with sessions and "ErrorDocument 401" redirects to a valid wiki topic, does not properly handle failed login attempts, which allows remote attackers to read arbitrary content by cancelling out of a failed authentication with a valid username and invalid password.. EPSS estimates a 2.05% chance of exploitation in the next 30 days.
Description
TWiki 4.0.5 and earlier, when running under Apache 1.3 using ApacheLogin with sessions and "ErrorDocument 401" redirects to a valid wiki topic, does not properly handle failed login attempts, which allows remote attackers to read arbitrary content by cancelling out of a failed authentication with a valid username and invalid password.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Twiki | Twiki | <= 4.0.5 |
References
- http://secunia.com/advisories/23189Vendor Advisory
- http://secunia.com/advisories/23189Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-6071?
How severe is CVE-2006-6071?
How do I fix CVE-2006-6071?
Are you affected by CVE-2006-6071?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
