Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2006-4542
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-4542

Description:
Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read CGI program source code, list directories, and possibly execute programs.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/28699

ST
  1016776
  1016777

SAID
  Secunia Advisory: SA21690
  Secunia Advisory: SA22087
  Secunia Advisory: SA22114
  Secunia Advisory: SA22556

OSVDB
  28338
  28337

MISC
  http://jvn.jp/jp/JVN%2399776858/index.html
  http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/89_e.html

MANDRIVA
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:170

DEBIAN
  http://www.debian.org/security/2006/dsa-1199

CONFIRM
  http://webmin.com/security.html

BID
  19820


Return to the previous page.