Vulnerabilities
Vulnerable Software
Webmin:  >> Webmin  >> 0.97  Security Vulnerabilities
Cross-site scripting (XSS) vulnerability in Webmin before 1.500 and Usermin before 1.430 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS Score
4.3
EPSS Score
0.003
Published
2010-01-05
Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read CGI program source code, list directories, and possibly execute programs.
CVSS Score
6.8
EPSS Score
0.017
Published
2006-09-05
Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, with unknown impact.
CVSS Score
10.0
EPSS Score
0.003
Published
2005-05-02
Webmin 0.21 through 1.0 uses the same built-in SSL key for all installations, which allows remote attackers to eavesdrop or highjack the SSL session.
CVSS Score
6.4
EPSS Score
0.003
Published
2002-12-31


Contact Us

Shodan ® - All rights reserved