Overview
Webmin and Usermin do not properly sanitize user input. This vulnerability may allow a remote, unauthenticated user to view any file on the system running Webmin or Usermin.
Description
Webmin |
Impact
An attacker could read any file on the computer running Webmin or Usermin. |
Solution
Upgrade |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
The Webmin team has reported this vulnerability.
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | CVE-2006-3392 |
Severity Metric: | 9.53 |
Date Public: | 2006-06-30 |
Date First Published: | 2006-07-07 |
Date Last Updated: | 2006-08-01 18:09 UTC |
Document Revision: | 32 |