CVE-2004-0583 Information
Feb 14, 2021
cve
Description
The account lockout functionality in (1) Webmin 1.140 and (2) Usermin 1.070 does not parse certain character strings which allows remote attackers to conduct a brute force attack to guess user IDs and passwords.
Reference
http://marc.info/?l=bugtraq&m=108737059313829&w=2 http://www.debian.org/security/2004/dsa-526 http://www.gentoo.org/security/en/glsa/glsa-200406-12.xml http://www.gentoo.org/security/en/glsa/glsa-200406-15.xml http://www.lac.co.jp/security/csl/intelligence/SNSadvisory_e/75_e.html http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:074 http://www.securityfocus.com/bid/10474 http://www.securityfocus.com/bid/10523 http://www.webmin.com/changes-1.150.html https://exchange.xforce.ibmcloud.com/vulnerabilities/16334
Share on: