First published: Thu Jul 06 2006(Updated: )
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes such as "%01" are removed from the filename. NOTE: This is a different issue than CVE-2006-3274.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Usermin Usermin | <=1.210 | |
Webmin Webmin | <=1.2.80 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.