Webmin before 0.5 does not restrict the number of invalid passwords that are entered for a valid username, which could allow remote attackers to gain privileges via brute force password cracking.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/9138 | mailing list patch vendor advisory |
http://www.webmin.com/webmin/changes.html | vendor advisory |
http://www.securityfocus.com/bid/98 | vdb entry |