Vulnerabilities > Webmin > Webmin > 0.92.1

DATE CVE VULNERABILITY TITLE RISK
2010-01-05 CVE-2009-4568 Cross-Site Scripting vulnerability in Webmin Usermin and Webmin
Cross-site scripting (XSS) vulnerability in Webmin before 1.500 and Usermin before 1.430 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
webmin CWE-79
4.3
2006-09-05 CVE-2006-4542 Cross-Site Scripting vulnerability in multiple products
Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read CGI program source code, list directories, and possibly execute programs.
6.8
2002-12-31 CVE-2002-1673 Unspecified vulnerability in Webmin
The web interface for Webmin 0.92 does not properly quote or filter script code in files that are displayed to the interface, which allows local users to execute script and possibly steal cookies by inserting the script into certain files or fields, such as a real user name entry in the passwd file.
local
low complexity
webmin
3.6
2002-12-31 CVE-2002-1672 Unspecified vulnerability in Webmin 0.92/0.92.1
Webmin 0.92, when installed from an RPM, creates /var/webmin with insecure permissions (world readable), which could allow local users to read the root user's cookie-based authentication credentials and possibly hijack the root user's session using the credentials.
local
low complexity
webmin
2.1
2002-08-12 CVE-2002-0757 Authentication Bypass vulnerability in Webmin / Usermin
(1) Webmin 0.96 and (2) Usermin 0.90 with password timeouts enabled allow local and possibly remote attackers to bypass authentication and gain privileges via certain control characters in the authentication information, which can force Webmin or Usermin to accept arbitrary username/session ID combinations.
network
low complexity
usermin webmin
7.5
2002-08-12 CVE-2002-0756 Cross-Site Scripting vulnerability in Webmin / Usermin Login
Cross-site scripting vulnerability in the authentication page for (1) Webmin 0.96 and (2) Usermin 0.90 allows remote attackers to insert script into an error page and possibly steal cookies.
network
low complexity
usermin webmin
7.5