Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Webmin Number Of NVD 87 CRITICAL 6 HIGH 27 MEDIUM 49 LOW 5
URL https://www.webmin.com/
Explanation Webmin is a web-based interface for Unix system administration. Using a modern web browser, you can set up user accounts, Apache, DNS, file sharing, and more. Webmin eliminates the need to manually edit Unix configuration files such as / etc / passwd, and allows you to manage your system from the console or remotely.

Excerpted and translated from [https://www.webmin.com/
Tag
  • BSD License

Add Information URL
No Type Name URL
1 https://www.webmin.com/download.html
2 https://www.webmin.com/changes.html
3 https://www.webmin.com/security.html

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
71 Webmin 2 2.610 Nov. 23, 2025 Aug. 23, 2022 0 0 19 0
72 Webmin 1 1.470, March 14, 2023 Sept. 12, 2002 6 20 31 2
73 Webmin 0 0.990 July 1, 2002 Oct. 5, 1997 2 17 23 4
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
71 -
7.5
HIGH The web mail functionality in Usermin 1.x and Webmin 1.x allows remote attackers to execute arbitrary commands via shell metacharacters in an e-mail message. NVD-CWE-Other
CVE-2004-1468 cpe:2.3:a:webmin:webmin:1.1.50:*
cpe:2.3:a:webmin:webmin:1.1.40:*
cpe:2.3:a:webmin:webmin:1.1.30:*
cpe:2.3:a:w…
2017-07-11 10:31
2004-12-31
Show GitHub Exploit DB Packet Storm
72 -
2.1
LOW The maketemp.pl script in Usermin 1.070 and 1.080 allows local users to overwrite arbitrary files at install time via a symlink attack on the /tmp/.usermin directory. NVD-CWE-Other
CVE-2004-0559 cpe:2.3:a:webmin:webmin:1.1.50:*
cpe:2.3:a:webmin:webmin:1.1.40:*
cpe:2.3:a:webmin:webmin:1.1.30:*
cpe:2.3:a:w…
2017-07-11 10:30
2004-10-20
Show GitHub Exploit DB Packet Storm
73 -
5.0
MEDIUM Unknown vulnerability in Webmin 1.140 allows remote attackers to bypass access control rules and gain read access to configuration information for a module. NVD-CWE-Other
CVE-2004-0582 cpe:2.3:a:webmin:webmin:1.1.40:* 2017-07-11 10:30
2004-08-6
Show GitHub Exploit DB Packet Storm
74 -
5.0
MEDIUM The account lockout functionality in (1) Webmin 1.140 and (2) Usermin 1.070 does not parse certain character strings, which allows remote attackers to conduct a brute force attack to guess user IDs a… NVD-CWE-Other
CVE-2004-0583 cpe:2.3:a:webmin:webmin:1.1.40:* 2017-07-11 10:30
2004-08-6
Show GitHub Exploit DB Packet Storm
75 -
10.0
HIGH miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded strings during Basic auth… NVD-CWE-Other
CVE-2003-0101 cpe:2.3:a:webmin:webmin:1.0.60:*
cpe:2.3:a:webmin:webmin:1.0.50:*
2016-10-18 11:29
2003-03-3
Show GitHub Exploit DB Packet Storm
76 -
2.1
LOW Webmin 0.92, when installed from an RPM, creates /var/webmin with insecure permissions (world readable), which could allow local users to read the root user's cookie-based authentication credentials … NVD-CWE-Other
CVE-2002-1672 cpe:2.3:a:webmin:webmin:0.92:*
cpe:2.3:a:webmin:webmin:0.92.1:*
2017-07-11 10:29
2002-12-31
Show GitHub Exploit DB Packet Storm
77 -
3.6
LOW The web interface for Webmin 0.92 does not properly quote or filter script code in files that are displayed to the interface, which allows local users to execute script and possibly steal cookies by … NVD-CWE-Other
CVE-2002-1673 cpe:2.3:a:webmin:webmin:0.92:*
cpe:2.3:a:webmin:webmin:0.92.1:*
cpe:2.3:a:webmin:webmin:0.91:*
cpe:2.3:a:webmi…
2017-07-11 10:29
2002-12-31
Show GitHub Exploit DB Packet Storm
78 -
6.4
MEDIUM Webmin 0.21 through 1.0 uses the same built-in SSL key for all installations, which allows remote attackers to eavesdrop or highjack the SSL session. NVD-CWE-Other
CVE-2002-1947 cpe:2.3:a:webmin:webmin:1.0.00:*
cpe:2.3:a:webmin:webmin:0.99:*
cpe:2.3:a:webmin:webmin:0.98:*
cpe:2.3:a:webmi…
2008-09-6 05:31
2002-12-31
Show GitHub Exploit DB Packet Storm
79 -
10.0
HIGH The Printer Administration module for Webmin 0.990 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the printer name. NVD-CWE-Other
CVE-2002-2201 cpe:2.3:a:webmin:webmin:*:* 0.99 2008-09-6 05:32
2002-12-31
Show GitHub Exploit DB Packet Storm
80 -
9.3
HIGH The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to arbitrary files and execute arbitrary commands via remote_for… CWE-264
Permissions, Privileges, and Access Controls
CVE-2002-2360 cpe:2.3:a:webmin:webmin:0.990:*
cpe:2.3:a:webmin:webmin:0.980:*
cpe:2.3:a:webmin:webmin:0.970:*
cpe:2.3:a:webm…
2008-09-6 05:33
2002-12-31
Show GitHub Exploit DB Packet Storm