Reportedly the 'ttacab.cgi' script bundled with Tarantella Enterprise 3 is prone to a remote cross-site scripting vulnerability. This issue is due to a failure of the application to sufficiently sanitize user supplied URI input. This issue may be leveraged to steal cookie based authentication credentials, other attacks are possible as well.
Reportedly the 'ttacab.cgi' script bundled with Tarantella Enterprise 3 is prone to a remote cross-site scripting vulnerability. This issue is due to a failure of the application to sufficiently sanitize user supplied URI input. This issue may be leveraged to steal cookie based authentication credentials, other attacks are possible as well.