Summary: | www-apps/horde-turba test.php IMAP XSS (CVE-2008-4182) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Robert Buchholz (RETIRED) <rbu> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED WORKSFORME | ||
Severity: | normal | CC: | web-apps, wrobel |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | B3 [ebuild] | ||
Package list: | Runtime testing required: | --- |
Description
Robert Buchholz (RETIRED)
2008-09-24 15:26:55 UTC
The test.php scripts are automatically handled with "chmod 000" within the horde.eclass. These scripts are not meant to be used by the outside world as they provide detailed server information so they are locked down by default. Opening this hole requires the user to actively change permissions on these files. I consider this irrelevant. Objections? (In reply to comment #1) > Objections? No. |