CVE Vulnerabilities

CVE-1999-1074

Published: Dec 31, 1999 | Modified: Sep 09, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Webmin before 0.5 does not restrict the number of invalid passwords that are entered for a valid username, which could allow remote attackers to gain privileges via brute force password cracking.

Affected Software

Name Vendor Start Version End Version
Webmin Webmin 0.1 (including) 0.1 (including)
Webmin Webmin 0.2 (including) 0.2 (including)
Webmin Webmin 0.3 (including) 0.3 (including)
Webmin Webmin 0.4 (including) 0.4 (including)
Webmin Webmin 0.21 (including) 0.21 (including)
Webmin Webmin 0.22 (including) 0.22 (including)
Webmin Webmin 0.31 (including) 0.31 (including)
Webmin Webmin 0.41 (including) 0.41 (including)
Webmin Webmin 0.42 (including) 0.42 (including)

References