Vulnerabilities > CVE-2007-0108 - Unspecified vulnerability in Novell Client 4.91

047910
CVSS 6.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
novell
nessus

Summary

nwgina.dll in Novell Client 4.91 SP3 for Windows 2000/XP/2003 does not delete user profiles during a Terminal Service or Citrix session, which allows remote authenticated users to invoke alternate user profiles.

Vulnerable Configurations

Part Description Count
Application
Novell
1

Nessus

NASL familyWindows
NASL idNOVELL_TID2974970.NASL
descriptionThe file
last seen2020-06-01
modified2020-06-02
plugin id23978
published2007-01-06
reporterThis script is Copyright (C) 2007-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/23978
titleNovell Client TS/Citrix Session Arbitrary User Profile Invocation