cgi-bin/main in Sun Ray Server Software 2.0 and 3.0 before 20070123 allows local users to obtain the utadmin password by reading a web server's log file, or by conducting a different, unspecified local attack.
| Software | From | Fixed in |
|---|---|---|
| sun / ray_server_software | 3.0 | 3.0.x |
| sun / ray_server_software | 2.0 | 2.0.x |