| From the Debian advisory:
Ansgar Burchardt, Mike O'Connor and Philipp Kern discovered multiple
vulnerabilities in DTC, a web control panel for admin and accounting
hosting services:
CVE-2011-3195:
A possible shell insertion has been found in the mailing list
handling.
CVE-2011-3196:
Unix rights for the apache2.conf were set incorrectly (world
readable).
CVE-2011-3197:
Incorrect input sanitising for the $_SERVER["addrlink"] parameter
could lead to SQL insertion.
CVE-2011-3198:
DTC was using the -b option of htpasswd, possibly revealing
password in clear text using ps or reading /proc.
CVE-2011-3199:
A possible HTML/javascript insertion vulnerability has been found
in the DNS & MX section of the user panel. |