CVE-2005-3630 Information

Description

Fedora Directory Server before 10 allows remote attackers to obtain sensitive information such as the password from adm.conf via an IFRAME element probably involving an Apache httpd.conf configuration that orders \allow\ directives before \deny\ directives.

Reference

http://directory.fedora.redhat.com/wiki/FDS10Announcement http://secunia.com/advisories/18939 http://www.securityfocus.com/bid/16729 https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=121994 https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=174837

Share on: