CVE-2006-3392

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/07/2006
Last modified:
03/04/2025

Description

Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes such as "%01" are removed from the filename. NOTE: This is a different issue than CVE-2006-3274.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:usermin:usermin:*:*:*:*:*:*:*:* 1.210 (including)
cpe:2.3:a:webmin:webmin:*:*:*:*:*:*:*:* 1.2.80 (including)


References to Advisories, Solutions, and Tools