Vulnerability Name: | CCN-35331 | ||||||
Published: | 2005-01-08 | ||||||
Updated: | 2005-01-08 | ||||||
Summary: | Webmin could allow a remote attacker to obtain sensitive information. Failed login attempts are not limited. An attacker could exploit this vulnerability to enumerate valid usernames and passwords, perform dictionary or brute force attacks, and possibly gain unauthorized administrative access to the system. | ||||||
CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||
CVSS v2 Severity: | 7.6 High (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C) 6.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
| ||||||
Vulnerability Consequences: | Obtain Information | ||||||
References: | Source: CCN Type: Webmin Web site Webmin Source: XF Type: UNKNOWN webmin-admin-information-disclosure(35331) | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |