7.2
CVSSv2

CVE-2001-1074

Published: 28/05/2001 Updated: 10/10/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Webmin 0.84 and previous versions does not properly clear the HTTP_AUTHORIZATION environment variable when the web server is restarted, which makes authentication information available to all CGI programs and allows local users to gain privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

webmin webmin 0.6

webmin webmin 0.7

webmin webmin 0.5

webmin webmin 0.80

webmin webmin 0.83

webmin webmin 0.84