CVE
- Id
- 19496
- CVE No.
- CVE-2006-3392
- Status
- Candidate
- Description
- Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes such as "%01" are removed from the filename. NOTE: This is a different issue than CVE-2006-3274.
- Phase
- Assigned (20060706)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
175170 | 19496 | CVE-2006-3392 | BUGTRAQ:20060709 Webmin / Usermin Arbitrary File Disclosure Vulnerability exploit | View |
175171 | 19496 | CVE-2006-3392 | URL:http://www.securityfocus.com/archive/1/archive/1/439653/100/0/threaded | View |
175172 | 19496 | CVE-2006-3392 | BUGTRAQ:20060715 Webmin / Usermin Arbitrary File Disclosure Vulnerability Perl | View |
175173 | 19496 | CVE-2006-3392 | URL:http://www.securityfocus.com/archive/1/archive/1/440493/100/0/threaded | View |
175174 | 19496 | CVE-2006-3392 | BUGTRAQ:20060710 Re: Webmin / Usermin Arbitrary File Disclosure Vulnerability exploit | View |
175175 | 19496 | CVE-2006-3392 | URL:http://www.securityfocus.com/archive/1/archive/1/440125/100/0/threaded | View |
175176 | 19496 | CVE-2006-3392 | BUGTRAQ:20060715 Re: Webmin / Usermin Arbitrary File Disclosure Vulnerability exploit | View |
175177 | 19496 | CVE-2006-3392 | URL:http://www.securityfocus.com/archive/1/440466/100/0/threaded | View |
175178 | 19496 | CVE-2006-3392 | CONFIRM:http://www.webmin.com/changes.html | View |
175179 | 19496 | CVE-2006-3392 | VIM:20060630 Webmin traversal - changelog | View |
175180 | 19496 | CVE-2006-3392 | URL:http://attrition.org/pipermail/vim/2006-June/000912.html | View |
175181 | 19496 | CVE-2006-3392 | VIM:20060711 Re: Webmin traversal - changelog | View |
175182 | 19496 | CVE-2006-3392 | URL:http://attrition.org/pipermail/vim/2006-July/000923.html | View |
175183 | 19496 | CVE-2006-3392 | DEBIAN:DSA-1199 | View |
175184 | 19496 | CVE-2006-3392 | URL:http://www.debian.org/security/2006/dsa-1199 | View |
175185 | 19496 | CVE-2006-3392 | GENTOO:GLSA-200608-11 | View |
175186 | 19496 | CVE-2006-3392 | URL:http://security.gentoo.org/glsa/glsa-200608-11.xml | View |
175187 | 19496 | CVE-2006-3392 | MANDRIVA:MDKSA-2006:125 | View |
175188 | 19496 | CVE-2006-3392 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2006:125 | View |
175189 | 19496 | CVE-2006-3392 | CERT-VN:VU#999601 | View |
175190 | 19496 | CVE-2006-3392 | URL:http://www.kb.cert.org/vuls/id/999601 | View |
175191 | 19496 | CVE-2006-3392 | BID:18744 | View |
175192 | 19496 | CVE-2006-3392 | URL:http://www.securityfocus.com/bid/18744 | View |
175193 | 19496 | CVE-2006-3392 | VUPEN:ADV-2006-2612 | View |
175194 | 19496 | CVE-2006-3392 | URL:http://www.vupen.com/english/advisories/2006/2612 | View |
175195 | 19496 | CVE-2006-3392 | OSVDB:26772 | View |
175196 | 19496 | CVE-2006-3392 | URL:http://www.osvdb.org/26772 | View |
175197 | 19496 | CVE-2006-3392 | SECUNIA:20892 | View |
175198 | 19496 | CVE-2006-3392 | URL:http://secunia.com/advisories/20892 | View |
175199 | 19496 | CVE-2006-3392 | SECUNIA:21105 | View |
175200 | 19496 | CVE-2006-3392 | URL:http://secunia.com/advisories/21105 | View |
175201 | 19496 | CVE-2006-3392 | SECUNIA:21365 | View |
175202 | 19496 | CVE-2006-3392 | URL:http://secunia.com/advisories/21365 | View |
175203 | 19496 | CVE-2006-3392 | SECUNIA:22556 | View |