First published: Sun Mar 16 2014(Updated: )
Cross-site scripting (XSS) vulnerability in view.cgi in Webmin before 1.680 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webmin | <=1.670 | |
Webmin | =1.600 | |
Webmin | =1.610 | |
Webmin | =1.620 | |
Webmin | =1.630 | |
Webmin | =1.640 | |
Webmin | =1.650 | |
Webmin | =1.660 | |
<=1.670 | ||
=1.600 | ||
=1.610 | ||
=1.620 | ||
=1.630 | ||
=1.640 | ||
=1.650 | ||
=1.660 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0339 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2014-0339, upgrade Webmin to version 1.680 or later.
CVE-2014-0339 affects Webmin versions earlier than 1.680, specifically versions 1.600 to 1.670.
CVE-2014-0339 allows remote attackers to perform cross-site scripting attacks by injecting arbitrary web scripts or HTML.
CVE-2014-0339 can be exploited in the Webmin interface, specifically in the view.cgi functionality.