CVE-2007-3156: XSS
Multiple cross-site scripting (XSS) vulnerabilities in pamlogin.cgi in Webmin before 1.350 and Usermin before 1.280 allow remote attackers to inject arbitrary web script or HTML via the (1) cid, (2) message, or (3) question parameter. NOTE: some of these details are obtained from third party information.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3156?
CVE-2007-3156 is considered a moderate severity cross-site scripting vulnerability.
How do I fix CVE-2007-3156?
To fix CVE-2007-3156, upgrade to Webmin version 1.350 or Usermin version 1.280 or later.
What software is affected by CVE-2007-3156?
CVE-2007-3156 affects Webmin versions prior to 1.350 and Usermin versions prior to 1.280.
What should I do if I cannot upgrade to fix CVE-2007-3156?
If upgrading is not possible, consider disabling the affected functionality to mitigate the risk of exploitation.
Can CVE-2007-3156 be exploited remotely?
Yes, CVE-2007-3156 allows remote attackers to inject arbitrary web script or HTML via specific parameters.