Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2005-3042
Description:miniserv.pl in Webmin before 1.230 and Usermin before 1.160, when "full PAM conversations" is enabled, allows remote attackers to bypass authentication by spoofing session IDs via certain metacharacters (line feed or carriage return).
Test IDs: 1.3.6.1.4.1.25623.1.0.55435   1.3.6.1.4.1.25623.1.0.55609  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2005-3042
BugTraq ID: 14889
http://www.securityfocus.com/bid/14889
Bugtraq: 20050921 [SNS Advisory No.83] Webmin/Usermin PAM Authentication Bypass Vulnerability (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2005-09/0257.html
http://www.gentoo.org/security/en/glsa/glsa-200509-17.xml
http://jvn.jp/jp/JVN%2340940493/index.html
http://www.mandriva.com/security/advisories?name=MDKSA-2005:176
http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/83_e.html
http://www.osvdb.org/19575
http://secunia.com/advisories/16858
http://secunia.com/advisories/17282
http://securityreason.com/securityalert/17
SuSE Security Announcement: SUSE-SR:2005:024 (Google Search)
http://www.novell.com/linux/security/advisories/2005_24_sr.html
http://www.vupen.com/english/advisories/2005/1791




© 1998-2025 E-Soft Inc. All rights reserved.