LWN.net Logo

kolab-server: password disclosure

Package(s):kolab-server CVE #(s):
Created:September 15, 2008 Updated:September 17, 2008
Description:

From the Mandriva advisory:

Gavin McCullagh of Griffith College Dublin reported an issue in Kolab v1 where user passwords were being recorded in the Apache log files due to Kolab using HTTP GET requests rather than HTTP POST requests. This would allow any users with access to the Apache log files to harvest user passwords and possibly other sensitive data.

Alerts:
Mandriva MDVSA-2008:193 2008-09-13

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds