ttawebtop.cgi in Tarantella Enterprise 3.20 on SPARC Solaris and Linux, and 3.1x and 3.0x including 3.11.903, allows remote attackers to view directory contents via an empty pg parameter.
| Software | From | Fixed in |
|---|---|---|
| tarantella / tarantella_enterprise | 3.0 | 3.0.x |
| tarantella / tarantella_enterprise | 3.20 | 3.20.x |
| tarantella / tarantella_enterprise | 3.10 | 3.10.x |