Description: A vulnerability has been reported in TWiki, which potentially can be exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to an error in the handling of file uploads where a filename has multiple file extensions. This can be exploited to upload malicious script files inside the pub directory (e.g. a PHP script).
Successful exploitation may allow execution of script code depending on the HTTP server configuration (it requires e.g. an Apache server with the "mod_mime" module installed).
The vulnerability has been reported in the following releases:
* TWikiRelease04x00x03
* TWikiRelease04x00x02
* TWikiRelease04x00x01
* TWikiRelease04x00x00
* TWikiRelease04Sep2004
* TWikiRelease03Sep2004
* TWikiRelease02Sep2004
* TWikiRelease01Sep2004
* TWikiRelease01Feb2003
* TWikiRelease01Dec2001
* TWikiRelease01Dec2000
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.