Security Advisory

CVE-2014-3851

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2014-08-07 10:00:00
Last updated 2024-08-06 10:57:17
Assigner mitre
State PUBLISHED

Description

usr/lib/cgi-bin/create_passwd_file.py in Pyplate 0.08 uses world-readable permissions for passwd.db, which allows local users to obtain the administrator password by reading this file.