Unrated severityNVD Advisory· Published Mar 3, 2003· Updated Apr 16, 2026
CVE-2003-0101
CVE-2003-0101
Description
miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded strings during Basic authentication, which allows remote attackers to spoof a session ID and gain root privileges.
Affected products
18- cpe:2.3:a:engardelinux:guardian_digital_webtool:1.2:*:*:*:*:*:*:*
cpe:2.3:a:usermin:usermin:0.4:*:*:*:*:*:*:*+ 14 more
- cpe:2.3:a:usermin:usermin:0.4:*:*:*:*:*:*:*
- cpe:2.3:a:usermin:usermin:0.5:*:*:*:*:*:*:*
- cpe:2.3:a:usermin:usermin:0.6:*:*:*:*:*:*:*
- cpe:2.3:a:usermin:usermin:0.7:*:*:*:*:*:*:*
- cpe:2.3:a:usermin:usermin:0.8:*:*:*:*:*:*:*
- cpe:2.3:a:usermin:usermin:0.9:*:*:*:*:*:*:*
- cpe:2.3:a:usermin:usermin:0.91:*:*:*:*:*:*:*
- cpe:2.3:a:usermin:usermin:0.92:*:*:*:*:*:*:*
- cpe:2.3:a:usermin:usermin:0.93:*:*:*:*:*:*:*
- cpe:2.3:a:usermin:usermin:0.94:*:*:*:*:*:*:*
- cpe:2.3:a:usermin:usermin:0.95:*:*:*:*:*:*:*
- cpe:2.3:a:usermin:usermin:0.96:*:*:*:*:*:*:*
- cpe:2.3:a:usermin:usermin:0.97:*:*:*:*:*:*:*
- cpe:2.3:a:usermin:usermin:0.98:*:*:*:*:*:*:*
- cpe:2.3:a:usermin:usermin:0.99:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
17- www.iss.net/security_center/static/11390.phpnvdVendor Advisory
- patches.sgi.com/support/free/security/advisories/20030602-01-Invd
- archives.neohapsis.com/archives/hp/2003-q1/0063.htmlnvd
- archives.neohapsis.com/archives/linux/engarde/2003-q1/0008.htmlnvd
- marc.infonvd
- marc.infonvd
- marc.infonvd
- marc.infonvd
- secunia.com/advisories/8115nvd
- secunia.com/advisories/8163nvd
- www.ciac.org/ciac/bulletins/n-058.shtmlnvd
- www.debian.org/security/2003/dsa-319nvd
- www.lac.co.jp/security/english/snsadv_e/62_e.htmlnvd
- www.linuxsecurity.com/advisories/gentoo_advisory-2886.htmlnvd
- www.mandriva.com/security/advisoriesnvd
- www.securityfocus.com/bid/6915nvd
- www.securitytracker.com/idnvd
News mentions
0No linked articles in our index yet.