9.3
CVSSv2

CVE-2002-2360

Published: 31/12/2002 Updated: 05/09/2008
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The RPC module in Webmin 0.21 up to and including 0.99, when installed without root or admin privileges, allows remote malicious users to read and write to arbitrary files and execute arbitrary commands via remote_foreign_require and remote_foreign_call requests.

Vulnerable Product Search on Vulmon Subscribe to Product

webmin webmin 0.41

webmin webmin 0.51

webmin webmin 0.88

webmin webmin 0.92

webmin webmin 0.970

webmin webmin 0.990

webmin webmin 0.21

webmin webmin 0.22

webmin webmin 0.31

webmin webmin 0.93

webmin webmin 0.94

webmin webmin 0.950

webmin webmin 0.960

webmin webmin 0.77

webmin webmin 0.78

webmin webmin 0.79

webmin webmin 0.80

webmin webmin 0.42

webmin webmin 0.76

webmin webmin 0.85

webmin webmin 0.91

webmin webmin 0.980

Exploits

source: wwwsecurityfocuscom/bid/5591/info In cases where users of Webmin do not have root access on the underlying host, it may be possible to mount privilege escalation attacks on the underlying host This normally occurs in configurations where multiple Webmin client systems have access to a centralized Webmin server Webmin allows com ...