First published: Wed Jun 23 2004(Updated: )
The account lockout functionality in (1) Webmin 1.140 and (2) Usermin 1.070 does not parse certain character strings, which allows remote attackers to conduct a brute force attack to guess user IDs and passwords.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Usermin Usermin | =1.070 | |
Webmin Webmin | =1.1.40 | |
Debian Debian Linux | =3.0 | |
Debian Debian Linux | =3.0 | |
Debian Debian Linux | =3.0 | |
Debian Debian Linux | =3.0 | |
Debian Debian Linux | =3.0 | |
Debian Debian Linux | =3.0 | |
Debian Debian Linux | =3.0 | |
Debian Debian Linux | =3.0 | |
Debian Debian Linux | =3.0 | |
Debian Debian Linux | =3.0 | |
Debian Debian Linux | =3.0 | |
Debian Debian Linux | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.