Majordomo Config-file admin_password...

- AV AC AU C I A
发布: 2000-12-01
修订: 2025-04-13

Majordomo is a popular open-source e-mail list server written in Perl. There exists a common configuration error in Majordomo's authentication system that may allow for remote attackers to execute administrative commands. Majordomo authenticates list administrators using passwords each time an administrative command is issued. During authentication, the supplied password is first compared to the value of the admin_password option in the list configuration file. If the two match, the administrator is authenticated and the command is executed. If not, majordomo attempts to open a file in the lists directory with a filename in the format: "listname.passwd", where "listname" is the name of the current list. The password is then read from that file. Many Majordomo setup/installation guides instruct the user configuring Majordomo not to set a real password as the value of admin_password, rather assign the option the value of the filename to be opened containing the password (in the...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息