CVE-2006-4387
CVE-2006-4387
Apple Mac OS X 10.4 through 10.4.7, when the administrator clears the "Allow user to administer this computer" checkbox in System Preferences for a user, does not remove the user's account from the appserveradm or appserverusr groups, which still allows the user to manage WebObjects applications.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://lists.apple.com/archives/security-announce/2006/Sep/msg00002.htmlhttp://secunia.com/advisories/22187http://securitytracker.com/id?1016955https://exchange.xforce.ibmcloud.com/vulnerabilities/29296http://www.osvdb.org/29273http://www.securityfocus.com/bid/20271http://www.vupen.com/english/advisories/2006/3852