← Back

CVE-2003-0101

nvd nist
Published: Mar 3, 2003Modified: Apr 16, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded strings during Basic authentication, which allows remote attackers to spoof a session ID and gain root privileges.

Affected (18)

1 product
Guardian Digital Webtool
1 product
Usermin
1 product
Webmin
Configuration A
18 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.2
Usermin
Version 0.4
Version 0.5
Version 0.6
Version 0.7
Version 0.8
Version 0.91
Version 0.92
Version 0.93
Version 0.94
Version 0.95
Version 0.96
Version 0.97
Version 0.98
Version 0.99
Version 0.9
Webmin
Version 1.0.50
Version 1.0.60

References (34)

ftp://patches.sgi.com/support/free/security/advisories/20030602-01-I (unsafe URL)
Source: cve@mitre.org
Source: cve@mitre.org
Vendor Advisory
ftp://patches.sgi.com/support/free/security/advisories/20030602-01-I (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.