CVE-2006-3392: Medium severity Usermin Usermin vulnerability
Webmin before 1.290 and Usermin before 1.220 calls the simplifypath function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes such as "%01" are removed from the filename. NOTE: This is a different issue than CVE-2006-3274.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3392?
CVE-2006-3392 is classified as a high severity vulnerability due to its ability to allow unauthorized file access.
How do I fix CVE-2006-3392?
To fix CVE-2006-3392, upgrade Webmin to version 1.290 or higher and Usermin to version 1.220 or higher.
What systems are affected by CVE-2006-3392?
CVE-2006-3392 affects Webmin versions prior to 1.290 and Usermin versions prior to 1.220.
What type of attack is facilitated by CVE-2006-3392?
CVE-2006-3392 facilitates path traversal attacks, allowing attackers to read arbitrary files on the server.
Is there a workaround for CVE-2006-3392 if I cannot upgrade?
If upgrading is not possible, ensure proper file permissions are set to limit access to sensitive files.