webmin: session ID spoofing
Package(s): | webmin | CVE #(s): | CAN-2003-0101 | ||||||||
Created: | June 13, 2003 | Updated: | November 18, 2003 | ||||||||
Description: | miniserv.pl in the webmin package does not properly handle metacharacters, such as line feeds and carriage returns, in Base64-encoded strings used in Basic authentication. This vulnerability allows remote attackers to spoof a session ID, and thereby gain root privileges. | ||||||||||
Alerts: |
|