Description

The 'test' action, while useful for debugging, leaks way too much server info and possibly exposes a system to unnecessary attacks. For instance: If action=test reveals a Redhat FC1 server, then someone may decide to try the typical FC1 exploits against that system. The same goes for other systems. Additionally the action=test feature reveals path names and other data not useful for typical use.

-Jim P.

Steps to reproduce

  1. visit http://moinmoin.wikiwikiweb.de/?action=test

Example

Workaround

Put this into your wiki / farm config:

    actions_excluded = ["test"]

Plan


CategoryMoinMoinNoBug

MoinMoin: MoinMoinBugs/TestActionShowPrivateInfo (last edited 2008-06-16 19:45:50 by ThomasWaldmann)