Webmin 0.92, when installed from an RPM, creates /var/webmin with insecure permissions (world readable), which could allow local users to read the root user's cookie-based authentication credentials and possibly hijack the root user's session using the credentials.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2002-12-31 05:00
Updated : 2025-04-03 01:03
NVD link : CVE-2002-1672
Mitre link : CVE-2002-1672
CVE.ORG link : CVE-2002-1672
JSON object : View
Products Affected
webmin
- webmin
CWE