Vulnerability Name: | CVE-2001-1074 (CCN-6627) | ||||||||
Assigned: | 2001-05-26 | ||||||||
Published: | 2001-05-26 | ||||||||
Updated: | 2017-10-10 | ||||||||
Summary: | Webmin 0.84 and earlier does not properly clear the HTTP_AUTHORIZATION environment variable when the web server is restarted, which makes authentication information available to all CGI programs and allows local users to gain privileges. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CCN Type: Caldera International, Inc. Security Advisory CSSA-2001-019.1 Linux - webmin root account leak Source: CCN Type: Caldera International, Inc. Security Advisory CSSA-2001-019.0 webmin root account leak Source: BUGTRAQ Type: Vendor Advisory 20010526 Webmin Doesn't Clean Env (root exploit) Source: CCN Type: BugTraq Mailing List, Sat May 26 2001 - 15:55:35 CDT Webmin Doesn't Clean Env (root exploit) Source: CCN Type: BugTraq Mailing List, Tue May 29 2001 - 09:14:06 CDT Re: Webmin Doesn't Clean Env (root exploit) Source: MITRE Type: CNA CVE-2001-1074 Source: CALDERA Type: Patch, Vendor Advisory CSSA-2001-019.1 Source: MANDRAKE Type: Patch MDKSA-2001:059 Source: CCN Type: OSVDB ID: 1844 Webmin miniserv.pl Environment Variable Cleartext Password Local Disclosure Source: BID Type: Exploit, Patch, Vendor Advisory 2795 Source: CCN Type: BID-2795 Webmin Environment Variable Information Disclosure Vulnerability Source: CCN Type: Webmin Web site Webmin Source: XF Type: UNKNOWN webmin-gain-information(6627) Source: XF Type: UNKNOWN webmin-gain-information(6627) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |