Re: [webmin-devel] XSS in Webmin 1.540 + exploit for privilege escalation

Javier Bassi <[email protected]> Sat, 23 Apr 2011 22:17:44 -0300
Newsgroups gmane.comp.web.webmin.devel
Message-ID <[email protected]>
On Sat, Apr 23, 2011 at 10:11 PM, Jamie Cameron <[email protected]> wrote:
> Hi Javier,
>
> Thanks for reporting this - I hadn't considered this attack
> vector, as I didn't realize that chfn could be used to modify a user's
> real name.
>
> I have created a fix which you can see at :
>
> https://github.com/webmin/webmin/commit/46e3d3ad195dcdc1af1795c96b6e0dc778fb6881
>
> Also an update for the Users and Groups module can be found at
> http://www.webmin.com/updates.html , and will be available from within
> the Webmin UI.
>
>  - Jamie

Thanks for the fast fix!

Javier

------------------------------------------------------------------------------
Fulfilling the Lean Software Promise
Lean software platforms are now widely adopted and the benefits have been 
demonstrated beyond question. Learn why your peers are replacing JEE 
containers with lightweight application servers - and what you can gain 
from the move. http://p.sf.net/sfu/vmware-sfemails
-
Forwarded by the Webmin development list at [email protected]
To remove yourself from this list, go to
http://lists.sourceforge.net/lists/listinfo/webadmin-devel