Network Associates PGP Keyserver 7.0 allows remote attackers to bypass authentication and access the administrative web interface via URLs that directly access cgi-bin instead of keyserver/cgi-bin for the programs (1) console, (2) cs, (3) multi_config and (4) directory.
| Software | From | Fixed in |
|---|---|---|
| pgp / keyserver | 7.0.1 | 7.0.1.x |
| pgp / keyserver | 7.0 | 7.0.x |