Security Advisory

CVE-2002-1672

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2005-06-21 04:00:00
Last updated 2024-08-08 03:34:55
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Webmin 0.92, when installed from an RPM, creates /var/webmin with insecure permissions (world readable), which could allow local users to read the root user's cookie-based authentication credentials and possibly hijack the root user's session using the credentials.