Webmin Password Brute Force Vulnerability

BID:98

Info

Webmin Password Brute Force Vulnerability

Bugtraq ID: 98
Class: Origin Validation Error
CVE:
Remote: Yes
Local: Unknown
Published: May 01 1998 12:00AM
Updated: May 01 1998 12:00AM
Credit: This vulnerability was reported to the BugTraq mailing list by Jiva DeVoe <[email protected]> on Fri, 1 May 1998.
Vulnerable: Webmin Webmin 0.42
Webmin Webmin 0.41
Webmin Webmin 0.31
Webmin Webmin 0.22
Webmin Webmin 0.21
Webmin Webmin 0.4
Webmin Webmin 0.3
Webmin Webmin 0.2
Webmin Webmin 0.1
Not Vulnerable: Webmin Webmin 0.51
Webmin Webmin 0.5

Discussion

Webmin Password Brute Force Vulnerability

Webmin is a web-based interface for system administration for Unix. Using any browser that supports tables and forms, you can setup user accounts, Apache, DNS, file sharing and so on.

Webmin consists of a simple web server, and a number of CGI programs which directly update system files like /etc/inetd.conf and /etc/passwd. The web server and all CGI programs are written in Perl version 5, and use no external modules. This means that you only need a Perl binary to run Webmin.

Webmin has an error which allows users to both guess valid usernames and attempt brute force password attacks against machines running webmin.

If you enter an invalid username in the username and password prompt displayed by Webmin, you are allowed in to the webmin main screen. You don't have access to the modules, but this allows the user to see that webmin is on the machine. Further, if you enter a valid username but an invalid password, the system gives you an access denied error, thus, you can determine, based on the response from the system, what a valid username is and what an invalid username is. Webmin should respond identically whether it's a valid username or not.

Users are given an indefinite number of attempts at entering a valid password for a valid username. Other services send you to a default "Access denied" URL or something to that effect, but webmin just keeps prompting for a valid password over and over if an invalid password is entered. This makes for simple password cracking attempts via brute force.

Exploit / POC

Webmin Password Brute Force Vulnerability

Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].

Solution / Fix

Webmin Password Brute Force Vulnerability

Solution:
This vulnerability has been fixed in version 0.5 or later. You can download the latest version from http://www.webmin.com/webmin/download/

References

Webmin Password Brute Force Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report