First published: Mon May 28 2001(Updated: )
Webmin 0.84 and earlier does not properly clear the HTTP_AUTHORIZATION environment variable when the web server is restarted, which makes authentication information available to all CGI programs and allows local users to gain privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webmin Webmin | =0.7 | |
Webmin Webmin | =0.6 | |
Webmin Webmin | =0.83 | |
Webmin Webmin | =0.84 | |
Webmin Webmin | =0.80 | |
Webmin Webmin | =0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.