Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Webmin 2FA requirement bypass
Vulnerability Description
Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.640, for Webmin accounts that require a second authentication factor (typically TOTP), an attacker with knowledge of the username and password can bypass the 2FA requirement by using Basic authentication. Webmin is a web-based system administration tool for Unix-like servers. As a workaround, apply the patch from commit da18a16c84ae5c0b78cad79609cb0efb174000ec manually.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
认证机制不恰当
Vulnerability Title
Webmin 授权问题漏洞
Vulnerability Description
Webmin是Webmin团队开源的一套基于Web的用于类Unix操作系统中的系统管理工具。 Webmin 2.640之前版本存在授权问题漏洞,该漏洞源于身份验证问题,可能导致知道用户名和密码的攻击者通过Basic认证绕过双因素认证。
CVSS Information
N/A
Vulnerability Type
N/A