Network Associates PGP Keyserver 7.0 allows remote attackers to bypass authentication and access the administrative web interface via URLs that directly access cgi-bin instead of keyserver/cgi-bin for the programs (1) console, (2) cs, (3) multi_config and (4) directory.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Keyserver | Pgp | 7.0 (including) | 7.0 (including) |
Keyserver | Pgp | 7.0.1 (including) | 7.0.1 (including) |