CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1054 | CVE-1999-1074 | Entry | Webmin before 0.5 does not restrict the number of invalid passwords that are entered for a valid username, which could allow remote attackers to gain privileges via brute force password cracking. | View | |||
56224 | CVE-2012-2981 | Candidate | Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary Perl code via a crafted file associated with the type (aka monitor type name) parameter. | Assigned (20120530) | None (candidate not yet proposed) | View | |
6056 | CVE-2002-1672 | Candidate | Webmin 0.92, when installed from an RPM, creates /var/webmin with insecure permissions (world readable), which could allow local users to read the root user"s cookie-based authentication credentials and possibly hijack the root user"s session using the credentials. | Assigned (20050621) | None (candidate not yet proposed) | View | |
3878 | CVE-2001-1074 | Entry | Webmin 0.84 and earlier does not properly clear the HTTP_AUTHORIZATION environment variable when the web server is restarted, which makes authentication information available to all CGI programs and allows local users to gain privileges. | View | |||
3043 | CVE-2001-0222 | Entry | webmin 0.84 and earlier allows local users to overwrite and create arbitrary files via a symlink attack. | View |
Page 243 of 20943, showing 5 records out of 104715 total, starting on record 1211, ending on 1215