CVE-2006-4246: Low severity Usermin Usermin vulnerability
Usermin before 1.220 (20060629) allows remote attackers to read arbitrary files, possibly related to chfn/save.cgi not properly handling an empty shell parameter, which results in changing root's shell instead of the shell of a specified user.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4246?
CVE-2006-4246 is considered a high severity vulnerability due to its potential for remote exploitation and ability to read arbitrary files.
How do I fix CVE-2006-4246?
To fix CVE-2006-4246, upgrade Usermin to version 1.220 or later which addresses the vulnerability.
What versions of Usermin are affected by CVE-2006-4246?
CVE-2006-4246 affects multiple versions of Usermin, including 0.4 through 1.210.
What type of vulnerability is CVE-2006-4246?
CVE-2006-4246 is a file read vulnerability that allows remote attackers to read sensitive files.
Is CVE-2006-4246 still a relevant vulnerability?
Yes, CVE-2006-4246 remains relevant for systems running affected versions of Usermin that have not been updated.