miniserv.pl in Webmin before 1.230 and Usermin before 1.160, when full PAM conversations is enabled, allows remote attackers to bypass authentication by spoofing session IDs via certain metacharacters (line feed or carriage return).
Name | Vendor | Start Version | End Version |
---|---|---|---|
Usermin | Usermin | 1.150 (including) | 1.150 (including) |
Webmin | Webmin | 1.2.20 (including) | 1.2.20 (including) |