CVE
- Id
- 20350
- CVE No.
- CVE-2006-4246
- Status
- Candidate
- Description
- Usermin before 1.220 (20060629) allows remote attackers to read arbitrary files, possibly related to chfn/save.cgi not properly handling an empty shell parameter, which results in changing root"s shell instead of the shell of a specified user.
- Phase
- Assigned (20060821)
- Votes
- None (candidate not yet proposed)
- Comments