|
[Japanese]
|
JVNDB-2007-000730
|
Webmin OS command injection vulnerability
|
Webmin, a web-based system management tool, contains a vulnerability that allows an unauthorized Webmin user to execute OS commands.
Webmin is a web-based system management tool. Webmin for Windows contains a vulnerability that allows an unauthorized Webmin user to execute OS commands by entering a specially crafted URL.
|
Base Metrics:
9.0 (High)
[IPA Score]
- Access Vector: Network
- Access Complexity: Low
- Authentication: Single Instance
- Confidentiality Impact: Complete
- Integrity Impact: Complete
- Availability Impact: Complete
|
|
|
Webmin Project
- Webmin 1.360 for Windows and earlier
|
|
An attacker could execute arbitrary OS commands with Local System privileges on a computer where Webmin is installed.
|
[Update the Software]
Webmin 1.370, in which the vulnerability is fixed, has been released by the Webmin project.
|
Webmin Project
|
- Improper Input Validation(CWE-20) [NVD Evaluation]
|
- CVE-2007-5066
|
- JVN : JVN#61208749
- National Vulnerability Database (NVD) : CVE-2007-5066
- Secunia Advisory : SA26885
- SecurityFocus : 25773
- ISS X-Force Database : 36759
- SecurityTracker : 1018731
- FrSIRT Advisories : FrSIRT/ADV-2007-3243
|
[2008/05/21]
Web page published
|