Vulnerabilities
Vulnerable Software
Usermin:  >> Usermin  Security Vulnerabilities
miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded strings during Basic authentication, which allows remote attackers to spoof a session ID and gain root privileges.
CVSS Score
10.0
EPSS Score
0.155
Published
2003-03-03
Cross-site scripting vulnerability in the authentication page for (1) Webmin 0.96 and (2) Usermin 0.90 allows remote attackers to insert script into an error page and possibly steal cookies.
CVSS Score
7.5
EPSS Score
0.01
Published
2002-08-12
(1) Webmin 0.96 and (2) Usermin 0.90 with password timeouts enabled allow local and possibly remote attackers to bypass authentication and gain privileges via certain control characters in the authentication information, which can force Webmin or Usermin to accept arbitrary username/session ID combinations.
CVSS Score
7.5
EPSS Score
0.006
Published
2002-08-12


Contact Us

Shodan ® - All rights reserved