CVE-2007-1276: CSRF
Multiple cross-site scripting (XSS) vulnerabilities in chooser.cgi in Webmin before 1.330 and Usermin before 1.260 allow remote attackers to inject arbitrary web script or HTML via a crafted filename.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1276?
CVE-2007-1276 is classified as a moderate severity vulnerability due to the potential for remote attackers to exploit it via cross-site scripting.
How do I fix CVE-2007-1276?
To fix CVE-2007-1276, upgrade to Webmin version 1.330 or later and Usermin version 1.260 or later.
What are the consequences of CVE-2007-1276 being exploited?
If exploited, CVE-2007-1276 can allow attackers to inject arbitrary web scripts or HTML, potentially compromising user data.
Which versions are affected by CVE-2007-1276?
CVE-2007-1276 affects multiple versions of Webmin and Usermin prior to their respective patched releases.
What is Webmin in relation to CVE-2007-1276?
Webmin is a web-based interface for system administration, and CVE-2007-1276 identifies vulnerabilities within its chooser.cgi script.