CVE-2006-2942

Publication date 20 June 2006

Last updated 17 July 2025


Ubuntu priority

Description

TWiki 4.0.0, 4.0.1, and 4.0.2 allows remote attackers to gain Twiki administrator privileges via a TWiki.TWikiRegistration form with a modified action attribute that references the Sandbox web instead of the user web, which can then be used to associate the user's login name with the WikiName of a member of the TWikiAdminGroup.

Read the notes from the security team

Status

Package Ubuntu Release Status
twiki 7.10 gutsy
Not affected
7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Not affected

Notes


fujitsu

Only 4.0.[0-2] affected. Not us.


Access our resources on patching vulnerabilities