Tarantella Enterprise 3 Install.CGI Application Server Password Saving Vulnerability
BID:4462
Info
Tarantella Enterprise 3 Install.CGI Application Server Password Saving Vulnerability
| Bugtraq ID: | 4462 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 05 2002 12:00AM |
| Updated: | Apr 05 2002 12:00AM |
| Credit: | Vulnerability discovery credited to Frank Ickstadt <[email protected]>. |
| Vulnerable: |
Tarantella Enterprise 3 3.20 0 Tarantella Enterprise 3 3.11 Tarantella Enterprise 3 3.10 |
| Not Vulnerable: | |
Discussion
Tarantella Enterprise 3 Install.CGI Application Server Password Saving Vulnerability
Enterprise 3 is a system administration package distributed and maintained by Tarantella Incorporated. It is available for the Unix and Linux platforms.
The install.cgi script does not correctly handle some configurations. The function to prevent the saving of configuration information such as passwords, which works correctly in the Java/Javascript package included with Tarantella, does not work properly in the install.cgi script. Because of this, it is possible for a user to save configuration data, such as the application server passwords, to their profile.
Enterprise 3 is a system administration package distributed and maintained by Tarantella Incorporated. It is available for the Unix and Linux platforms.
The install.cgi script does not correctly handle some configurations. The function to prevent the saving of configuration information such as passwords, which works correctly in the Java/Javascript package included with Tarantella, does not work properly in the install.cgi script. Because of this, it is possible for a user to save configuration data, such as the application server passwords, to their profile.
Exploit / POC
Tarantella Enterprise 3 Install.CGI Application Server Password Saving Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Tarantella Enterprise 3 Install.CGI Application Server Password Saving Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Tarantella Enterprise 3 Install.CGI Application Server Password Saving Vulnerability
References:
References:
- Enterprise 3 Product Page (Tarantella)