Unrated severityNVD Advisory· Published Aug 6, 2004· Updated Apr 16, 2026
CVE-2004-0583
CVE-2004-0583
Description
The account lockout functionality in (1) Webmin 1.140 and (2) Usermin 1.070 does not parse certain character strings, which allows remote attackers to conduct a brute force attack to guess user IDs and passwords.
Affected products
14cpe:2.3:o:debian:debian_linux:3.0:*:*:*:*:*:*:*+ 11 more
- cpe:2.3:o:debian:debian_linux:3.0:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:3.0:*:alpha:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:3.0:*:arm:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:3.0:*:hppa:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:3.0:*:ia-32:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:3.0:*:ia-64:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:3.0:*:m68k:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:3.0:*:mips:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:3.0:*:mipsel:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:3.0:*:ppc:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:3.0:*:s-390:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:3.0:*:sparc:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- www.securityfocus.com/bid/10474nvdPatchVendor Advisory
- www.securityfocus.com/bid/10523nvdPatchVendor Advisory
- marc.infonvd
- www.debian.org/security/2004/dsa-526nvd
- www.gentoo.org/security/en/glsa/glsa-200406-12.xmlnvd
- www.gentoo.org/security/en/glsa/glsa-200406-15.xmlnvd
- www.lac.co.jp/security/csl/intelligence/SNSadvisory_e/75_e.htmlnvd
- www.mandrakesecure.net/en/advisories/advisory.phpnvd
- www.webmin.com/changes-1.150.htmlnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/16334nvd
News mentions
0No linked articles in our index yet.