Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Format string vulnerability in miniserv.pl Perl web server in Webmin before 1.250 and Usermin before 1.180, with syslog logging enabled, allows remote attackers to cause a denial of service (crash or memory consumption) and possibly execute arbitrary code via format string specifiers in the username parameter to the login form, which is ultimately used in a syslog call. NOTE: the code execution might be associated with an issue in Perl.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Perl Webmin miniserv.pl格式化字符串漏洞
Vulnerability Description
Perl是一种免费且功能强大的编程语言。 在Webmin 1.250以前版本,和Usermin 1.180以前版本的Perl Web Server中,其miniserv.pl存在格式化字符串漏洞,这允许远程攻击者通过提供给登录窗体的username参数(这个参数最终会被syslog函数使用)来发起拒绝服务攻击,并可以执行任意的代码。 注意:这些代码执行可能与perl的问题有关系。
CVSS Information
N/A
Vulnerability Type
N/A