FreeBSD : webmin -- potential XSS attack via real name field (ec89dc70-2515-11e2-8eda-000a5e1e33c6)

high Nessus Plugin ID 62807

Synopsis

The remote FreeBSD host is missing a security-related update.

Description

The webmin updates site reports

Module: Change Passwords; Version: 1.600; Problem: Fix for potential XSS attack via real name field; Solution: New module.

Solution

Update the affected package.

See Also

http://www.webmin.com/updates.html

http://www.nessus.org/u?a9c8a51a

Plugin Details

Severity: High

ID: 62807

File Name: freebsd_pkg_ec89dc70251511e28eda000a5e1e33c6.nasl

Version: 1.5

Type: local

Published: 11/5/2012

Updated: 1/6/2021

Supported Sensors: Nessus

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:webmin, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 11/2/2012

Vulnerability Publication Date: 11/2/2012