Webmin before 0.5 does not restrict the number of invalid passwords that are entered for a valid username, which could allow remote attackers to gain privileges via brute force password cracking.
https://euvd.enisa.europa.eu/vulnerability/EUVD-1999-1055
http://www.webmin.com/webmin/changes.html