This one is scary. The session ID
spoofing vulnerability allows the "possibility that arbitrary
commands may be executed with root privileges."
Upgrading is strongly recommended. At a minimum avoid the
"preconditions for a successful exploit" by disabling
password timeouts under Webmin->Configuration->Authentication.
Posted Jun 1, 2002 1:58 UTC (Sat) by rjamestaylor (guest, #339)
[Link]
A seasoned Unix admin told me to avoid remote admin tools, especially web-based ones, at any cost. I didn't listen but with the revelation that such a security hole has existed until now (!) I have lost confidence in Webmin for the foreseeable future.