OMG. Is Webmin safe? I can see file codes in Chrome browser without login

Posted by Arwana on Server Fault See other posts from Server Fault or by Arwana
Published on 2010-04-02T11:38:19Z Indexed on 2010/04/02 11:43 UTC
Read the original article Hit count: 234

Filed under:

When Im in File Manager of Webmin, I can double click and see the codes of the files in new tab in Firefox with its specific URL.

But when I remove ?rand=xxxx... after the file.php and paste the URL in Chrome browser, I still can see the codes.

This is the URL I just pasted in the Chrome browser

http://xxx.xxx.xxx.xxx:10000/file/show.cgi/var/www/html/mysite.com/files/file.php

And then, I logout of webmin, and I change the file.php with other file, I can see the codes.

OMG. Is Webmin safe? and how to secure this?

© Server Fault or respective owner

Related posts about webmin