CVE-2002-0757
N/A
N/A
Summary
(1) Webmin 0.96 and (2) Usermin 0.90 with password timeouts enabled allow local and possibly remote attackers to bypass authentication and gain privileges via certain control characters in the authentication information, which can force Webmin or Usermin to accept arbitrary username/session ID combinations.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.iss.net/security_center/static/9037.php
- http://www.securityfocus.com/bid/4700
- http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-033.php
- http://online.securityfocus.com/archive/1/271466
References
- http://www.iss.net/security_center/static/9037.php
- http://www.securityfocus.com/bid/4700
- http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-033.php
- http://online.securityfocus.com/archive/1/271466
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.