TWiki Remote File Disclosure and Command Execution Vulnerability
Description
A vulnerability has been identified in TWiki, which could be exploited by attackers to gain knowledge of sensitive information or execute arbitrary code. This issue is caused by an input validation error in the "bin/configure" script that does not validate the "image" parameter, which could be exploited by attackers to disclose the contents of arbitrary files via directory traversal or execute malicious code.
Vulnerable Products
Vulnerable Software: TWiki versions prior to 4.2.3