积极预防 及时发现
快速响应 力保恢复
iPlanet Calendar Server 5.0p2及其早期版本允许远程攻击者通过从配置文件中...
发布时间:2001-08-02 信息来源:管理员

CNCVE编号:CNCVE-20010620 CVE编号:CAN-2001-0620 安全级别:中 漏洞中文描述: iPlanet Calendar Server 5.0p2及其早期版本允许远程攻击者通过从配置文件中获得明文管理员用户名和口令来访问Netscape Admin Server LADP数据库和阅读任意文件。 漏洞英文描述: iPlanet Calendar Server 5.0p2 and earlier allows a local attacker to gain access to the Netscape Admin Server (NAS) LDAP database and read arbitrary files by obtaining the cleartext administrator username and password from the configuration file. 漏洞参考: Reference: BUGTRAQ:20010418 iplanet calendar server 5.0p2 exposes Netscape Admin Server master password Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0320.html Reference: XF:iplanet-calendar-plaintext-password(6402) Reference: 系统类型:其他 漏洞类型:设计错误