Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Webmin 0.84 and earlier does not properly clear the HTTP_AUTHORIZATION environment variable when the web server is restarted, which makes authentication information available to all CGI programs and allows local users to gain privileges.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Webmin提升特权漏洞
Vulnerability Description
Webmin 0.84及其早期版本在web服务器重启后不正确的清除HTTP_AUTHORIZATION环境变量,该漏洞给所有的CGI程序提供认证信息变量且本地用户利用该漏洞提升特权。
CVSS Information
N/A
Vulnerability Type
N/A