ttawebtop.cgi in Tarantella Enterprise 3.20 on SPARC Solaris and Linux, and 3.1x and 3.0x including 3.11.903, allows remote attackers to view directory contents via an empty pg parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Tarantella_enterprise | Tarantella | 3.0 (including) | 3.0 (including) |
| Tarantella_enterprise | Tarantella | 3.10 (including) | 3.10 (including) |
| Tarantella_enterprise | Tarantella | 3.20 (including) | 3.20 (including) |