Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Webmin 1.050 - 1.060 remote exploit Feb 24 2003 12:45PM
Carl Livitt (carl learningshophull co uk)

Hi all,

Attached is an exploit for the latest Webmin vulnerability. It relies on a
non-default setting (passdelay) to be enabled.

Webmin can verify user authentication by use of a session ID (SID) that is
assigned when a user successfully authenticates to Webmin. It is possible to
inject a fak...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus