| twiki-announce list: | To get immediate alerts of high priority security issues, please join the low-volume twiki-announce list - details at TWikiAnnounceMailingList |
|---|
twiki/data, twiki/lib, twiki/templates and all their subdirectories and the files they include should be configured in your Apache server so that they are not visible through URLs.
To check your site:
/lib/TWiki.cfg is available via the web, by simply browsing to it.lib directory is located, it is usually on the same directory level as the pub directory. Have a look at the images on your wiki to find out which one that is, as they are usually stored below the pub directory. Of course, the easiest way to find the correct URL is to look how the files are located on your server (and taking in account the instructions you set in httpd.conf - especially the Alias setting).
lib/TWiki is exposed as a URL. Try a Google search on your site,example.org with your site)
| # | Action | Date/ Deadline | Status | Who |
|---|---|---|---|---|
| 1. | User discloses issue to TWikiSecurityMailingList | 2005-09-18 | Done | MoritzNaumann |
| 2. | Investigate issue | 2005-09-20 | Done | CrawfordCurrie |
| 3. | Publish advisory in Codev web | 2005-09-27 evening PDT | Done | PeterThoeny |
| 4. | Send alert to TWikiAnnounceMailingList and TWikiDevMailingList (as part of SecurityAlertExecuteCommandsWithInclude advisory) | 2005-09-27 evening PDT | Done | PeterThoeny |
| 5. | Extended advisory in Codev web | 2005-09-28 noon UTC | Done | MoritzNaumann |