If this link produces a file with anything other than a plain php and html script, then we have security problems on this site. In other words, if that script is rendered, then we have the security problem. TWiki should not be running scripts from the pub/... area.

