|
|
| |
|
| |
kolab-server: password disclosure
| Package(s): | kolab-server |
CVE #(s): | |
| Created: | September 15, 2008 |
Updated: | September 17, 2008 |
| Description: |
From the Mandriva advisory:
Gavin McCullagh of Griffith College Dublin reported an issue in Kolab
v1 where user passwords were being recorded in the Apache log files
due to Kolab using HTTP GET requests rather than HTTP POST requests.
This would allow any users with access to the Apache log files to
harvest user passwords and possibly other sensitive data.
|
| Alerts: |
|
( Log in to post comments)
|
|
|