PT-2002-1778 · Webmin+1 · Webmin+1

Publicado

2002-07-26

·

Atualizado

2008-09-05

·

CVE-2002-0757

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Webmin version 0.96 Usermin version 0.90
Description The issue allows local and possibly remote attackers to bypass authentication and gain privileges via certain control characters in the authentication information. This can force the software to accept arbitrary username/session ID combinations.
Recommendations For Webmin version 0.96, update to a version that does not have the password timeout enabled or apply a configuration change to disable the vulnerable authentication mechanism. For Usermin version 0.90, update to a version that does not have the password timeout enabled or apply a configuration change to disable the vulnerable authentication mechanism. As a temporary workaround, consider restricting access to the authentication module to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0757

Produtos afetados

Usermin
Webmin