CVE-2004-1468: High severity Usermin Usermin vulnerability
Published Dec 31, 2004
·Updated
The web mail functionality in Usermin 1.x and Webmin 1.x allows remote attackers to execute arbitrary commands via shell metacharacters in an e-mail message.
Affected Software
22 affected components
Usermin Usermin=1.000
Usermin Usermin=1.010
Usermin Usermin=1.020
Usermin Usermin=1.030
Usermin Usermin=1.040
Usermin Usermin=1.051
Usermin Usermin=1.060
Usermin Usermin=1.070
Usermin Usermin=1.080
webmin webmin=1.0.00
webmin webmin=1.0.20
webmin webmin=1.0.50
webmin webmin=1.0.60
webmin webmin=1.0.70
webmin webmin=1.0.80
webmin webmin=1.0.90
webmin webmin=1.1.00
webmin webmin=1.1.10
webmin webmin=1.1.21
webmin webmin=1.1.30
webmin webmin=1.1.40
webmin webmin=1.1.50
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Feb 13, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1468?
CVE-2004-1468 is considered a critical vulnerability that allows remote command execution.
2
How do I fix CVE-2004-1468?
To fix CVE-2004-1468, update Usermin and Webmin to the latest versions that have addressed this vulnerability.
3
Which versions are affected by CVE-2004-1468?
CVE-2004-1468 affects Usermin versions 1.000 to 1.080 and Webmin versions 1.0.00 to 1.1.50.
4
Can CVE-2004-1468 be exploited remotely?
Yes, CVE-2004-1468 can be exploited remotely by sending specially crafted email messages.
5
What protections can I implement against CVE-2004-1468?
Implement security best practices such as input validation and email sanitization to protect against CVE-2004-1468.