RedHat Piranha Virtual Server Package Plaintext Password Vulnerability

Password changes submitted to Red Hat Piranha via HTTP are insecurely passed as variables in a GET request. Unauthorized users could obtain the password by reading the httpd access log or by sniffing.


 

Privacy Statement
Copyright 2010, SecurityFocus