CVE-2002-1672

Webmin 0.92, when installed from an RPM, creates /var/webmin with insecure permissions (world readable), which could allow local users to read the root user's cookie-based authentication credentials and possibly hijack the root user's session using the credentials.

Scoring

CVSS base score
0
EPSS probability
0.11%
Published
2005-06-21
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs