>> Webmin and Usermin "miniserv.pl" Remote Format String Vulnerability
Title : Webmin and Usermin "miniserv.pl" Remote Format String Vulnerability VUPEN ID : VUPEN/ADV-2005-2660 CVE ID : CVE-2005-3912
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-11-29
Technical Description
A vulnerability has been identified in Webmin and Usermin, which could be exploited by remote attackers to cause a denial of service or potentially execute arbitrary commands. This flaw is due to a format string error in "miniserv.pl" when logging failed authentication attempts via syslog, which could be exploited by remote unauthenticated attackers to crash and possibly compromise a vulnerable server by supplying a specially crafted username to the web administration interface (port 10000).