First published: Fri Jul 26 2002(Updated: )
Cross-site scripting vulnerability in the authentication page for (1) Webmin 0.96 and (2) Usermin 0.90 allows remote attackers to insert script into an error page and possibly steal cookies.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webmin Usermin | =0.7 | |
Webmin Usermin | =0.8 | |
Webmin Usermin | =0.9 | |
Webmin | =0.91 | |
Webmin | =0.92 | |
Webmin | =0.92.1 | |
Webmin | =0.93 | |
Webmin | =0.94 | |
Webmin | =0.95 | |
Webmin | =0.96 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0756 is typically classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2002-0756, update Webmin and Usermin to the latest version that addresses this vulnerability.
CVE-2002-0756 affects Webmin versions 0.91 through 0.96.
CVE-2002-0756 affects Usermin versions 0.7 through 0.9.
CVE-2002-0756 enables attackers to perform cross-site scripting (XSS) attacks potentially allowing cookie theft.