Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Kenny Chen

#48854de 53,638
5CVSS total
Vulnerabilidades · 1
PT-2006-4284
5.0
2006-07-06
Webmin · Usermin · CVE-2006-3392
**Name of the Vulnerable Software and Affected Versions** Webmin versions prior to 1.290 Usermin versions prior to 1.220 **Description** The issue allows remote attackers to read arbitrary files by bypassing the removal of "../" sequences before certain bytes, such as "%01", are removed from the filename. This can be achieved using "..%01" sequences. **Recommendations** For Webmin versions prior to 1.290, update to version 1.290 or later to resolve the issue. For Usermin versions prior to 1.220, update to version 1.220 or later to resolve the issue.