CVE-2006-4542: XSS
Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read CGI program source code, list directories, and possibly execute programs.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4542?
CVE-2006-4542 has a medium severity rating due to its potential to facilitate various attacks such as cross-site scripting and unauthorized access to sensitive information.
How do I fix CVE-2006-4542?
To fix CVE-2006-4542, upgrade Webmin to version 1.296 or later and Usermin to version 1.226 or later.
What types of attacks can be executed using CVE-2006-4542?
CVE-2006-4542 can allow remote attackers to execute cross-site scripting attacks, read CGI program source code, list directories, and possibly execute programs.
Which versions of Webmin are affected by CVE-2006-4542?
Webmin versions prior to 1.296 are affected by CVE-2006-4542.
Which versions of Usermin are affected by CVE-2006-4542?
Usermin versions prior to 1.226 are affected by CVE-2006-4542.