First published: Tue Sep 05 2006(Updated: )
Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read CGI program source code, list directories, and possibly execute programs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webmin Webmin | =1.2.50 | |
Webmin Webmin | =0.97 | |
Usermin Usermin | =0.91 | |
Webmin Webmin | =0.22 | |
Webmin Webmin | =0.99 | |
Usermin Usermin | =1.070 | |
Webmin Webmin | =1.0.20 | |
Webmin Webmin | =1.0.51 | |
Webmin Webmin | =0.7 | |
Webmin Webmin | =1.0.10 | |
Usermin Usermin | =1.040 | |
Webmin Webmin | =0.88 | |
Usermin Usermin | =0.9 | |
Webmin Webmin | =0.4 | |
Usermin Usermin | =1.060 | |
Webmin Webmin | =1.1.50 | |
Webmin Webmin | =1.0.60 | |
Usermin Usermin | =0.8 | |
Usermin Usermin | =1.080 | |
Usermin Usermin | =1.100 | |
Webmin Webmin | =1.1.00 | |
Usermin Usermin | =1.210 | |
Webmin Webmin | =1.1.30 | |
Webmin Webmin | =0.96 | |
Webmin Webmin | =1.1.21 | |
Webmin Webmin | =0.51 | |
Webmin Webmin | =0.90 | |
Webmin Webmin | =0.93 | |
Webmin Webmin | =0.31 | |
Webmin Webmin | =0.42 | |
Webmin Webmin | =1.0.00 | |
Webmin Webmin | =1.0.90 | |
Webmin Webmin | =0.92 | |
Webmin Webmin | =0.78 | |
Usermin Usermin | =0.97 | |
Usermin Usermin | =0.99 | |
Usermin Usermin | =1.010 | |
Usermin Usermin | =0.6 | |
Usermin Usermin | =1.130 | |
Webmin Webmin | <=1.2.90 | |
Webmin Webmin | =1.2.80 | |
Usermin Usermin | =1.150 | |
Webmin Webmin | =1.2.30 | |
Usermin Usermin | =1.140 | |
Usermin Usermin | =0.96 | |
Webmin Webmin | =1.0.30 | |
Webmin Webmin | =1.2.20 | |
Webmin Webmin | =1.1.40 | |
Webmin Webmin | =0.21 | |
Webmin Webmin | =0.77 | |
Webmin Webmin | =1.1.20 | |
Usermin Usermin | =1.090 | |
Usermin Usermin | =1.020 | |
Webmin Webmin | =0.2 | |
Webmin Webmin | =0.85 | |
Webmin Webmin | =0.6 | |
Webmin Webmin | =0.41 | |
Webmin Webmin | =1.2.60 | |
Webmin Webmin | =0.95 | |
Webmin Webmin | =0.94 | |
Usermin Usermin | =0.5 | |
Usermin Usermin | =1.051 | |
Usermin Usermin | =1.000 | |
Usermin Usermin | =1.030 | |
Usermin Usermin | <=1.220 | |
Webmin Webmin | =0.83 | |
Usermin Usermin | =0.94 | |
Webmin Webmin | =1.2.70 | |
Usermin Usermin | =0.95 | |
Webmin Webmin | =0.84 | |
Webmin Webmin | =1.0.70 | |
Webmin Webmin | =0.3 | |
Webmin Webmin | =0.79 | |
Usermin Usermin | =0.92 | |
Usermin Usermin | =1.110 | |
Webmin Webmin | =0.76 | |
Usermin Usermin | =0.98 | |
Usermin Usermin | =0.93 | |
Webmin Webmin | =0.91 | |
Webmin Webmin | =1.0.50 | |
Webmin Webmin | =1.0.40 | |
Webmin Webmin | =0.80 | |
Webmin Webmin | =0.1 | |
Webmin Webmin | =0.5 | |
Webmin Webmin | =0.98 | |
Webmin Webmin | =1.0.80 | |
Usermin Usermin | =0.7 | |
Usermin Usermin | =1.120 | |
Webmin Webmin | =1.1.10 | |
Webmin Webmin | =1.2.40 | |
Webmin Webmin | =0.92.1 | |
Usermin Usermin | =0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.