Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
webmin webmin vulnerabilities and exploits
(subscribe to this query)
668
VMScore
CVE-2005-3042
miniserv.pl in Webmin prior to 1.230 and Usermin prior to 1.160, when "full PAM conversations" is enabled, allows remote malicious users to bypass authentication by spoofing session IDs via certain metacharacters (line feed or carriage return).
Usermin Usermin 1.150
Webmin Webmin 1.2.20
187
VMScore
CVE-2005-2731
Directory traversal vulnerability in Astaro Security Linux 6.0, when using Webmin, allows remote authenticated webmin users to read arbitrary files via a .. (dot dot) in the wfe_download parameter to index.fpl.
Astaro Security Linux 6.001
445
VMScore
CVE-2005-0427
The ebuild of Webmin prior to 1.170-r3 on Gentoo Linux includes the encrypted root password in the miniserv.users file when building a tbz2 of the webmin package, which allows remote malicious users to obtain and possibly crack the encrypted password.
Gentoo Webmin 1.160
Gentoo Webmin 1.150
Gentoo Webmin 1.140
Gentoo Webmin 1.170
890
VMScore
CVE-2005-1177
Unknown vulnerability in (1) Webmin and (2) Usermin prior to 1.200 causes Webmin to change permissions and ownership of configuration files, with unknown impact.
Webmin Webmin 0.97
Usermin Usermin 0.91
Webmin Webmin 0.99
Usermin Usermin 1.070
Webmin Webmin 1.0.20
Webmin Webmin 1.0.51
Webmin Webmin 0.7
Webmin Webmin 1.0.10
Usermin Usermin 1.040
Usermin Usermin 0.9
Webmin Webmin 0.4
Usermin Usermin 1.060
Webmin Webmin 1.0.60
Usermin Usermin 0.8
Usermin Usermin 1.080
Usermin Usermin 1.100
Webmin Webmin 1.1.00
Webmin Webmin 1.1.30
Webmin Webmin 0.96
Webmin Webmin 0.90
Webmin Webmin 0.93
Webmin Webmin 1.0.00
668
VMScore
CVE-2004-1468
The web mail functionality in Usermin 1.x and Webmin 1.x allows remote malicious users to execute arbitrary commands via shell metacharacters in an e-mail message.
Usermin Usermin 1.070
Webmin Webmin 1.0.20
Usermin Usermin 1.040
Usermin Usermin 1.060
Webmin Webmin 1.1.50
Webmin Webmin 1.0.60
Usermin Usermin 1.080
Webmin Webmin 1.1.00
Webmin Webmin 1.1.30
Webmin Webmin 1.1.21
Webmin Webmin 1.0.00
Webmin Webmin 1.0.90
Usermin Usermin 1.010
Webmin Webmin 1.1.40
Usermin Usermin 1.020
Usermin Usermin 1.051
Usermin Usermin 1.000
Usermin Usermin 1.030
Webmin Webmin 1.0.70
Webmin Webmin 1.0.50
Webmin Webmin 1.0.80
Webmin Webmin 1.1.10
187
VMScore
CVE-2004-0559
The maketemp.pl script in Usermin 1.070 and 1.080 allows local users to overwrite arbitrary files at install time via a symlink attack on the /tmp/.usermin directory.
Usermin Usermin 1.070
Webmin Webmin 1.0.20
Usermin Usermin 1.040
Usermin Usermin 1.060
Webmin Webmin 1.1.50
Webmin Webmin 1.0.60
Usermin Usermin 1.080
Webmin Webmin 1.1.00
Webmin Webmin 1.1.30
Webmin Webmin 1.1.21
Webmin Webmin 1.0.00
Webmin Webmin 1.0.90
Usermin Usermin 1.010
Webmin Webmin 1.1.40
Usermin Usermin 1.020
Usermin Usermin 1.051
Usermin Usermin 1.000
Usermin Usermin 1.030
Webmin Webmin 1.0.70
Webmin Webmin 1.0.50
Webmin Webmin 1.0.80
Webmin Webmin 1.1.10
445
VMScore
CVE-2004-0582
Unknown vulnerability in Webmin 1.140 allows remote malicious users to bypass access control rules and gain read access to configuration information for a module.
Webmin Webmin 1.1.40
445
VMScore
CVE-2004-0583
The account lockout functionality in (1) Webmin 1.140 and (2) Usermin 1.070 does not parse certain character strings, which allows remote malicious users to conduct a brute force attack to guess user IDs and passwords.
Usermin Usermin 1.070
Webmin Webmin 1.1.40
Debian Debian Linux 3.0
1000
VMScore
CVE-2003-0101
miniserv.pl in (1) Webmin prior to 1.070 and (2) Usermin prior to 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded strings during Basic authentication, which allows remote malicious users to spoof a session ID and gai...
Usermin Usermin 0.91
Usermin Usermin 0.9
Webmin Webmin 1.0.60
Usermin Usermin 0.8
Usermin Usermin 0.97
Usermin Usermin 0.99
Usermin Usermin 0.6
Usermin Usermin 0.96
Usermin Usermin 0.5
Usermin Usermin 0.94
Usermin Usermin 0.95
Usermin Usermin 0.92
Usermin Usermin 0.98
Usermin Usermin 0.93
Webmin Webmin 1.0.50
Usermin Usermin 0.7
Engardelinux Guardian Digital Webtool 1.2
Usermin Usermin 0.4
1 EDB exploit
187
VMScore
CVE-2002-1672
Webmin 0.92, when installed from an RPM, creates /var/webmin with insecure permissions (world readable), which could allow local users to read the root user's cookie-based authentication credentials and possibly hijack the root user's session using the credentials.
Webmin Webmin 0.92
Webmin Webmin 0.92.1
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
TCP
CVE-2024-4577
CVE-2024-2695
CVE-2024-31870
injection
CVE-2024-3813
arbitrary code
CVE-2024-27801
CVE-2024-30120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
5
6
7
8
9
10
NEXT »