The RecentChanges feature in WikkaWiki (Wikka Wiki) before 1.1.6.3 allows remote attackers to obtain the names, and possibly revision notes and dates, of private pages via RSS feeds.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.attrition.org/pipermail/vim/2007-May/001607.html | mailing list |
http://www.vupen.com/english/advisories/2007/1725 | vdb entry vendor advisory |
http://wikkawiki.org/WikkaReleaseNotes | patch |
http://www.securityfocus.com/bid/23894 | vdb entry |
http://wush.net/trac/wikka/ticket/305 | |
http://osvdb.org/35827 | vdb entry |
http://secunia.com/advisories/25181 | patch vendor advisory third party advisory |