First published: Fri Dec 31 2004(Updated: )
The web mail functionality in Usermin 1.x and Webmin 1.x allows remote attackers to execute arbitrary commands via shell metacharacters in an e-mail message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webmin Usermin | =1.000 | |
Webmin Usermin | =1.010 | |
Webmin Usermin | =1.020 | |
Webmin Usermin | =1.030 | |
Webmin Usermin | =1.040 | |
Webmin Usermin | =1.051 | |
Webmin Usermin | =1.060 | |
Webmin Usermin | =1.070 | |
Webmin Usermin | =1.080 | |
Webmin | =1.0.00 | |
Webmin | =1.0.20 | |
Webmin | =1.0.50 | |
Webmin | =1.0.60 | |
Webmin | =1.0.70 | |
Webmin | =1.0.80 | |
Webmin | =1.0.90 | |
Webmin | =1.1.00 | |
Webmin | =1.1.10 | |
Webmin | =1.1.21 | |
Webmin | =1.1.30 | |
Webmin | =1.1.40 | |
Webmin | =1.1.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1468 is considered a critical vulnerability that allows remote command execution.
To fix CVE-2004-1468, update Usermin and Webmin to the latest versions that have addressed this vulnerability.
CVE-2004-1468 affects Usermin versions 1.000 to 1.080 and Webmin versions 1.0.00 to 1.1.50.
Yes, CVE-2004-1468 can be exploited remotely by sending specially crafted email messages.
Implement security best practices such as input validation and email sanitization to protect against CVE-2004-1468.