Mr. DJ
03-26-2003, 04:30 AM
We found a huge bug in the cobalt raq550 software, I' ver already mailed sun, but they do not react!
When you log in as a siteadmin to the raq, you will have an url like this one:
http://www.alkeninternet.nl:444/nav/cList.php?root=sitemanageRoot&group=site1&hostname=www.alkeninternet.nl&goto=base_userList
you see there is site1 in it, just change it to another sitenumber and you will see another site's siteadmin! But in the other siteadmin you can just look at everything, you don't have the rights to change usernames,paswords etc. But you can see more then should be possible!
When you log in as a siteadmin to the raq, you will have an url like this one:
http://www.alkeninternet.nl:444/nav/cList.php?root=sitemanageRoot&group=site1&hostname=www.alkeninternet.nl&goto=base_userList
you see there is site1 in it, just change it to another sitenumber and you will see another site's siteadmin! But in the other siteadmin you can just look at everything, you don't have the rights to change usernames,paswords etc. But you can see more then should be possible!
