Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hm72-qxg7-34pg

Опубликовано: 03 мая 2022
Источник: github
Github: Не прошло ревью

Описание

miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded strings during Basic authentication, which allows remote attackers to spoof a session ID and gain root privileges.

miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded strings during Basic authentication, which allows remote attackers to spoof a session ID and gain root privileges.

EPSS

Процентиль: 94%
0.15499
Средний

Связанные уязвимости

nvd
больше 22 лет назад

miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded strings during Basic authentication, which allows remote attackers to spoof a session ID and gain root privileges.

debian
больше 22 лет назад

miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 do ...

EPSS

Процентиль: 94%
0.15499
Средний