<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>WebProNews &#187; Webmin</title>
	<atom:link href="http://www.webpronews.com/tag/webmin/feed" rel="self" type="application/rss+xml" />
	<link>http://www.webpronews.com</link>
	<description>Breaking News in Tech, Search, Social, &#38; Business</description>
	<lastBuildDate>Sun, 12 Feb 2012 17:24:19 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Webmin, Usermin Need Updates</title>
		<link>http://www.webpronews.com/webmin-usermin-need-updates-2006-09</link>
		<comments>http://www.webpronews.com/webmin-usermin-need-updates-2006-09#comments</comments>
		<pubDate>Fri, 01 Sep 2006 18:12:55 +0000</pubDate>
		<dc:creator>WebProNews Staff</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[perl]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[Usermin]]></category>
		<category><![CDATA[Webmin]]></category>

		<guid isPermaLink="false">http://www.webpronews.com/?p=31264</guid>
		<description><![CDATA[The French Security Incident Response Team (FrSIRT) has reported a pair of vulnerabilities in Webmin and Usermin that could be exploited by remote attackers.
]]></description>
			<content:encoded><![CDATA[<p>The French Security Incident Response Team (FrSIRT) has reported a pair of vulnerabilities in Webmin and Usermin that could be exploited by remote attackers.</p>
<p><a href=http://www.frsirt.com/english/advisories/2006/3424 class=bluelink>FrSIRT</a> said in its advisory that the pair of flaws pose problems for users of the <a href=http://www.webmin.com class=bluelink>Webmin</a> and Usermin web-based interfaces. Both are written in Perl 5 and employ CGI scripts deliver their functionality.</p>
<p>The advisory described the two issues, as reported to FrSIRT by Keigo Yamazaki, Little eArth Corporation:</p>
<p><i>
<div style=margin-left:10px; margin-right:10px>The first issue is due to an error when handling malformed URLs, which could be exploited by attackers to cause malicious scripting code to be executed by the user&#8217;s browser.</p>
<p>The second flaw is due to an error when handling malformed URLs, which could be exploited by attackers to display the source code or arbitrary CGI and Perl scripts.</p></div>
<p></i><br />
The flaws pose a moderate risk to systems running vulnerable versions of Webmin, as they are remotely exploitable. Cross-site scripting would be the attack vector used, according to the information posted at <a href=http://secunia.com/advisories/21690/ class=bluelink>Secunia</a> about the issues:</p>
<p><i>
<div style=margin-left:10px; margin-right:10px>1) Some input passed in a NULL character (&#8220;%00&#8243;) in the URL isn&#8217;t properly verified before being used. This can be exploited to disclose the source code of arbitrary CGI and Perl programs.</p>
<p>2) Some input passed in a NULL character (&#8220;%00&#8243;) in the URL isn&#8217;t properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user&#8217;s browser session in context of an affected site.</p></div>
<p></i><br />
Webmin developers have fixed both vulnerabilities in the development version of Webmin, 1.296, and Usermin, version 1.226.  </p>
<p>System administrators on Unix use Webmin to make configuration changes for services and manage accounts. Usermin provides an interface for regular users to read mail and do other user-level functions. Blogger Chris Dorner <a href=http://chrisdo.org/articles/2006/08/09/webmin-server-administration-software class=bluelink>hosts</a> a walkthrough of Webmin and screenshots of it in action.</p>
<p>&#8212;</p>
<p>Add to <a href="http://del.icio.us/post" onclick="window.open('http://del.icio.us/post?v=4&#038;partner=wpn&#038;noui&#038;jump=close&#038;url='+encodeURIComponent(location.href)+'&#038;title='+encodeURIComponent(document.title),'delicious','toolbar=no,width=700,height=400'); return false;" CLASS="printMailTop"><img src=http://images1.ientrymail.com/webpronews/delicious-pic.png border=0> Del.icio.us</a> | <a href="javascript:void window.open('http://digg.com/submit?phase=2&#038;url='+encodeURIComponent(window.location.href)+'&#038;ei=UTF-8','popup','width=520px,height=420px,status=0,location=0,resizable=1,scrollbars=1,left=100,top=50',0)"><img src=http://images1.ientrymail.com/webpronews/digg-pic.png border=0> Digg</a>  | <a href="javascript:void window.open('http://myweb2.search.yahoo.com/myresults/bookmarklet?t='+encodeURIComponent(document.title)+'&#038;u='+encodeURIComponent(window.location.href)+'&#038;tag=Perl,Webmin,Usermin','popup','width=520px,height=420px,status=0,location=0,resizable=1,scrollbars=1,left=100,top=50',0)"><img src=http://images1.ientrymail.com/webpronews/yahoo-pic.png border=0> Yahoo! My Web</a> | <a href="javascript:location.href='http://www.furl.net/storeIt.jsp?u='+encodeURIComponent(document.location.href)+'&#038;t='+encodeURIComponent(document.title)+' '"><img src=http://images1.ientrymail.com/webpronews/furl-pic.png border=0> Furl</a></p>
<p>Bookmark WebProNews: <a href=http://www.webpronews.com><img src=http://images.ientrymail.com/webpronews/wpn-readit.jpg border=0></a> </p>
<p><script language=JavaScript src="http://aj.600z.com/aj/1095/0/vj?z=1&#038;dim=1088&#038;pos=15"></script></p>
<p>David Utter is a staff writer for WebProNews covering technology and business. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.webpronews.com/webmin-usermin-need-updates-2006-09/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 1/9 queries in 0.004 seconds using memcached
Object Caching 193/206 objects using memcached

Served from: webpronews.com @ 2012-02-12 12:46:18 -->
