Wiki Server in Apple Mac OS X 10.6 before 10.6.3 does not enforce the service access control list (SACL) for weblogs during weblog creation, which allows remote authenticated users to publish content via HTTP requests.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html | vendor advisory |
http://support.apple.com/kb/HT4077 | patch vendor advisory |