PT-2001-2219 · Webmin · Webmin
Published
2001-05-28
·
Updated
2017-10-10
·
CVE-2001-1074
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Webmin versions 0.84 and earlier
Description
The issue arises from the improper clearing of the HTTP AUTHORIZATION environment variable when the web server is restarted. This makes authentication information available to all CGI programs, allowing local users to gain privileges.
Recommendations
For Webmin versions 0.84 and earlier, update to a version later than 0.84 to resolve the issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Webmin