Vulnerabilities > CVE-2001-1530 - Local Security vulnerability in Webmin 0.80/0.88

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
webmin
nessus

Summary

run.cgi in Webmin 0.80 and 0.88 creates temporary files with world-writable permissions, which allows local users to execute arbitrary commands.

Vulnerable Configurations

Part Description Count
Application
Webmin
2

Nessus

NASL familyCGI abuses
NASL idWEBMIN_0_80_88.NASL
descriptionAccording to its self-reported version, the Webmin install hosted on the remote host is 0.80 or 0.88. It is, therefore, affected by an issue in run.cgi which allows for the creation of temporary files with world-writable permissions, which could lead to arbitrary code execution.
last seen2020-06-01
modified2020-06-02
plugin id108535
published2018-03-22
reporterThis script is Copyright (C) 2018-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/108535
titleWebmin 0.80 / 0.88 world-writable files