Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2002-2360


The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to arbitrary files and execute arbitrary commands via remote_foreign_require and remote_foreign_call requests.


Published

2002-12-31T05:00:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 9.3 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.6

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application webmin webmin 0.21 Yes
Application webmin webmin 0.22 Yes
Application webmin webmin 0.31 Yes
Application webmin webmin 0.41 Yes
Application webmin webmin 0.42 Yes
Application webmin webmin 0.51 Yes
Application webmin webmin 0.76 Yes
Application webmin webmin 0.77 Yes
Application webmin webmin 0.78 Yes
Application webmin webmin 0.79 Yes
Application webmin webmin 0.80 Yes
Application webmin webmin 0.85 Yes
Application webmin webmin 0.88 Yes
Application webmin webmin 0.91 Yes
Application webmin webmin 0.92 Yes
Application webmin webmin 0.93 Yes
Application webmin webmin 0.94 Yes
Application webmin webmin 0.950 Yes
Application webmin webmin 0.960 Yes
Application webmin webmin 0.970 Yes
Application webmin webmin 0.980 Yes
Application webmin webmin 0.990 Yes

References