Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Webmin/Usermin Session ID Spoofing Unauthenticated Access Vulnerability

A vulnerability has been discovered in the 'Miniserv.pl' script used to invoke both Webmin and Usermin. Due to insufficient sanitization of client-supplied BASE64 encoded input, it is possible to inject a Session ID into the access control list.

Successful exploitation of this vulnerability may allow an attacker to bypass typical authentication procedures, thus gaining adminstrative access to a webmin/usermin interface.







 

Privacy Statement
Copyright 2008, SecurityFocus