ttawebtop.cgi in Tarantella Enterprise 3.20 on SPARC Solaris and Linux, and 3.1x and 3.0x including 3.11.903, allows remote attackers to view directory contents via an empty pg parameter.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=101190195430376&w=2 | mailing list |
http://www.tarantella.com/security/bulletin-03.html | url repurposed patch vendor advisory |