Overview
Webmin and Usermin do not properly sanitize user input. This vulnerability may allow a remote, unauthenticated user to view any file on the system running Webmin or Usermin.
Description
Webmin |
Impact
An attacker could read any file on the computer running Webmin or Usermin. |
Solution
Upgrade |
|
Vendor Information
CVSS Metrics
| Group | Score | Vector |
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental |
References
Acknowledgements
The Webmin team has reported this vulnerability.
This document was written by Ryan Giobbi.
Other Information
| CVE IDs: | CVE-2006-3392 |
| Severity Metric: | 9.53 |
| Date Public: | 2006-06-30 |
| Date First Published: | 2006-07-07 |
| Date Last Updated: | 2006-08-01 18:09 UTC |
| Document Revision: | 32 |