First published: Tue Sep 19 2006(Updated: )
Usermin before 1.220 (20060629) allows remote attackers to read arbitrary files, possibly related to chfn/save.cgi not properly handling an empty shell parameter, which results in changing root's shell instead of the shell of a specified user.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
Usermin Usermin | =0.91 | |
Usermin Usermin | =1.070 | |
Usermin Usermin | =1.040 | |
Usermin Usermin | =0.9 | |
Usermin Usermin | =1.060 | |
Usermin Usermin | =0.8 | |
Usermin Usermin | =1.080 | |
Usermin Usermin | =1.100 | |
Usermin Usermin | <=1.210 | |
Usermin Usermin | =0.97 | |
Usermin Usermin | =0.99 | |
Usermin Usermin | =1.010 | |
Usermin Usermin | =0.6 | |
Usermin Usermin | =1.130 | |
Usermin Usermin | =1.150 | |
Usermin Usermin | =1.140 | |
Usermin Usermin | =0.96 | |
Usermin Usermin | =1.090 | |
Usermin Usermin | =1.020 | |
Usermin Usermin | =0.5 | |
Usermin Usermin | =1.051 | |
Usermin Usermin | =1.000 | |
Usermin Usermin | =1.030 | |
Usermin Usermin | =0.94 | |
Usermin Usermin | =0.95 | |
Usermin Usermin | =0.92 | |
Usermin Usermin | =1.110 | |
Usermin Usermin | =0.98 | |
Usermin Usermin | =0.93 | |
Usermin Usermin | =0.7 | |
Usermin Usermin | =1.120 | |
Usermin Usermin | =0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.