CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1054  CVE-1999-1074  Entry  Webmin before 0.5 does not restrict the number of invalid passwords that are entered for a valid username, which could allow remote attackers to gain privileges via brute force password cracking.        View
56224  CVE-2012-2981  Candidate  Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary Perl code via a crafted file associated with the type (aka monitor type name) parameter.  Assigned (20120530)  None (candidate not yet proposed)    View
6056  CVE-2002-1672  Candidate  Webmin 0.92, when installed from an RPM, creates /var/webmin with insecure permissions (world readable), which could allow local users to read the root user"s cookie-based authentication credentials and possibly hijack the root user"s session using the credentials.  Assigned (20050621)  None (candidate not yet proposed)    View
3878  CVE-2001-1074  Entry  Webmin 0.84 and earlier does not properly clear the HTTP_AUTHORIZATION environment variable when the web server is restarted, which makes authentication information available to all CGI programs and allows local users to gain privileges.        View
3043  CVE-2001-0222  Entry  webmin 0.84 and earlier allows local users to overwrite and create arbitrary files via a symlink attack.        View

Page 243 of 20943, showing 5 records out of 104715 total, starting on record 1211, ending on 1215

Actions