Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read CGI program source code, list directories, and possibly execute programs.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:16
Type | Values Removed | Values Added |
---|---|---|
References | () http://jvn.jp/jp/JVN%2399776858/index.html - Patch | |
References | () http://secunia.com/advisories/21690 - Patch, Vendor Advisory | |
References | () http://secunia.com/advisories/22087 - | |
References | () http://secunia.com/advisories/22114 - | |
References | () http://secunia.com/advisories/22556 - | |
References | () http://securitytracker.com/id?1016776 - | |
References | () http://securitytracker.com/id?1016777 - | |
References | () http://webmin.com/security.html - Patch | |
References | () http://www.debian.org/security/2006/dsa-1199 - | |
References | () http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/89_e.html - Patch, Vendor Advisory | |
References | () http://www.mandriva.com/security/advisories?name=MDKSA-2006:170 - | |
References | () http://www.osvdb.org/28337 - | |
References | () http://www.osvdb.org/28338 - | |
References | () http://www.securityfocus.com/bid/19820 - | |
References | () http://www.vupen.com/english/advisories/2006/3424 - Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/28699 - |
Information
Published : 2006-09-05 23:04
Updated : 2024-11-21 00:16
NVD link : CVE-2006-4542
Mitre link : CVE-2006-4542
CVE.ORG link : CVE-2006-4542
JSON object : View
Products Affected
usermin
- usermin
webmin
- webmin
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')