CVE
- Id
- 5146
- CVE No.
- CVE-2002-0756
- Status
- Candidate
- Description
- Cross-site scripting vulnerability in the authentication page for (1) Webmin 0.96 and (2) Usermin 0.90 allows remote attackers to insert script into an error page and possibly steal cookies.
- Phase
- Proposed (20020726)
- Votes
- ACCEPT(2) Armstrong, Cole | NOOP(4) Christey, Cox, Foat, Wall
- Comments
- Christey> This *might* be vendor acknowledgement: | URL:http://www.geocrawler.com/lists/3/SourceForge/12082/0/8595354/ | | However, the person who"s credited by the vendor found *TWO* | authentication-related vulnerabilities at about the same time, | and the vendor is clearly fixing "a" vulnerability. So, which | issue did the vendor fix? Which issue is the vendor | acknowledging - CVE-2002-0757 or CVE-2002-0756?