Local unprivileged users can access the RNN Guestbook gbpass.pl file if set up according to the RNN software recommendations. Access to this file allows an attacker go read the Guestbook administrative password in plaintext.
Classification
Unknown or Incomplete
Solution
Currently, there are no known upgrades or patches to correct this issue. It is possible to correct the flaw by disabling all access to the guestbook scripts until a patch or upgrade is made available.