CVE-2006-3274: Medium severity webmin webmin vulnerability
Published Jun 28, 2006
·Updated
Directory traversal vulnerability in Webmin before 1.280, when run on Windows, allows remote attackers to read arbitrary files via \ (backslash) characters in the URL to certain directories under the web root, such as the image directory.
Affected Software
5 affected components
webmin webmin=1.2.50
webmin webmin=1.2.30
webmin webmin=1.2.60
webmin webmin=1.2.40
webmin webmin<=1.2.70
Event History
Jun 28, 2006
CVE Published
10:05 PM
Jun 29, 2006
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-3274?
CVE-2006-3274 is categorized as a medium-severity vulnerability due to its potential for unauthorized file access.
2
How do I fix CVE-2006-3274?
To fix CVE-2006-3274, update Webmin to version 1.280 or later, where the vulnerability is patched.
3
What versions of Webmin are affected by CVE-2006-3274?
CVE-2006-3274 affects Webmin versions up to and including 1.270.
4
Can CVE-2006-3274 be exploited remotely?
Yes, CVE-2006-3274 can be exploited remotely by attackers using specially crafted URLs.
5
What type of vulnerability is CVE-2006-3274?
CVE-2006-3274 is a directory traversal vulnerability that allows attackers to read arbitrary files on the server.