CVE
- Id
- 19496
- CVE No.
- CVE-2006-3392
- Status
- Candidate
- Description
- Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes such as "%01" are removed from the filename. NOTE: This is a different issue than CVE-2006-3274.
- Phase
- Assigned (20060706)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
| Id | CVE Id | CVE No. | Reference | Actions |
|---|---|---|---|---|
| 175170 | 19496 | CVE-2006-3392 | BUGTRAQ:20060709 Webmin / Usermin Arbitrary File Disclosure Vulnerability exploit | View |
| 175171 | 19496 | CVE-2006-3392 | URL:http://www.securityfocus.com/archive/1/archive/1/439653/100/0/threaded | View |
| 175172 | 19496 | CVE-2006-3392 | BUGTRAQ:20060715 Webmin / Usermin Arbitrary File Disclosure Vulnerability Perl | View |
| 175173 | 19496 | CVE-2006-3392 | URL:http://www.securityfocus.com/archive/1/archive/1/440493/100/0/threaded | View |
| 175174 | 19496 | CVE-2006-3392 | BUGTRAQ:20060710 Re: Webmin / Usermin Arbitrary File Disclosure Vulnerability exploit | View |
| 175175 | 19496 | CVE-2006-3392 | URL:http://www.securityfocus.com/archive/1/archive/1/440125/100/0/threaded | View |
| 175176 | 19496 | CVE-2006-3392 | BUGTRAQ:20060715 Re: Webmin / Usermin Arbitrary File Disclosure Vulnerability exploit | View |
| 175177 | 19496 | CVE-2006-3392 | URL:http://www.securityfocus.com/archive/1/440466/100/0/threaded | View |
| 175178 | 19496 | CVE-2006-3392 | CONFIRM:http://www.webmin.com/changes.html | View |
| 175179 | 19496 | CVE-2006-3392 | VIM:20060630 Webmin traversal - changelog | View |
| 175180 | 19496 | CVE-2006-3392 | URL:http://attrition.org/pipermail/vim/2006-June/000912.html | View |
| 175181 | 19496 | CVE-2006-3392 | VIM:20060711 Re: Webmin traversal - changelog | View |
| 175182 | 19496 | CVE-2006-3392 | URL:http://attrition.org/pipermail/vim/2006-July/000923.html | View |
| 175183 | 19496 | CVE-2006-3392 | DEBIAN:DSA-1199 | View |
| 175184 | 19496 | CVE-2006-3392 | URL:http://www.debian.org/security/2006/dsa-1199 | View |
| 175185 | 19496 | CVE-2006-3392 | GENTOO:GLSA-200608-11 | View |
| 175186 | 19496 | CVE-2006-3392 | URL:http://security.gentoo.org/glsa/glsa-200608-11.xml | View |
| 175187 | 19496 | CVE-2006-3392 | MANDRIVA:MDKSA-2006:125 | View |
| 175188 | 19496 | CVE-2006-3392 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2006:125 | View |
| 175189 | 19496 | CVE-2006-3392 | CERT-VN:VU#999601 | View |
| 175190 | 19496 | CVE-2006-3392 | URL:http://www.kb.cert.org/vuls/id/999601 | View |
| 175191 | 19496 | CVE-2006-3392 | BID:18744 | View |
| 175192 | 19496 | CVE-2006-3392 | URL:http://www.securityfocus.com/bid/18744 | View |
| 175193 | 19496 | CVE-2006-3392 | VUPEN:ADV-2006-2612 | View |
| 175194 | 19496 | CVE-2006-3392 | URL:http://www.vupen.com/english/advisories/2006/2612 | View |
| 175195 | 19496 | CVE-2006-3392 | OSVDB:26772 | View |
| 175196 | 19496 | CVE-2006-3392 | URL:http://www.osvdb.org/26772 | View |
| 175197 | 19496 | CVE-2006-3392 | SECUNIA:20892 | View |
| 175198 | 19496 | CVE-2006-3392 | URL:http://secunia.com/advisories/20892 | View |
| 175199 | 19496 | CVE-2006-3392 | SECUNIA:21105 | View |
| 175200 | 19496 | CVE-2006-3392 | URL:http://secunia.com/advisories/21105 | View |
| 175201 | 19496 | CVE-2006-3392 | SECUNIA:21365 | View |
| 175202 | 19496 | CVE-2006-3392 | URL:http://secunia.com/advisories/21365 | View |
| 175203 | 19496 | CVE-2006-3392 | SECUNIA:22556 | View |