The version of TWiki installed on the remote host allows access to
the 'configure' script and fails to sanitize the 'image' parameter
of that script of directory traversal sequences before returning the
file contents when the 'action' parameter is set to 'image'. An
unauthenticated attacker can leverage this issue to view arbitrary
files on the remote host subject to the privileges of the web server
user id. .