Vulnerability Name: | CVE-2002-0757 (CCN-9037) | ||||||||
Assigned: | 2002-05-07 | ||||||||
Published: | 2002-05-07 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | (1) Webmin 0.96 and (2) Usermin 0.90 with password timeouts enabled allow local and possibly remote attackers to bypass authentication and gain privileges via certain control characters in the authentication information, which can force Webmin or Usermin to accept arbitrary username/session ID combinations. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: SCO Security Advisory CSSA-2003-002.0 Webmin Cross-site Scripting and Session ID Spoofing Vulnerabilities Source: MITRE Type: CNA CVE-2002-0757 Source: BUGTRAQ Type: Exploit, Patch, Vendor Advisory 20020508 [SNS Advisory No.53] Webmin/Usermin Session ID Spoofing Vulnerability Source: XF Type: Patch, Vendor Advisory webmin-usermin-sessionid-spoof(9037) Source: CCN Type: SNS Advisory No.53 Webmin/Usermin Session ID Spoofing Vulnerability Source: MANDRAKE Type: Patch MDKSA-2002:033 Source: CCN Type: OSVDB ID: 10802 Webmin/Usermin Auth Information Control Character Bypass Arbitrary User Authentication Source: BID Type: Patch, Vendor Advisory 4700 Source: CCN Type: BID-4700 Webmin / Usermin Authentication Bypass Vulnerability Source: CCN Type: Webmin Web site Webmin Source: XF Type: UNKNOWN webmin-usermin-sessionid-spoof(9037) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |