CVE

Id
20350  
CVE No.
CVE-2006-4246  
Status
Candidate  
Description
Usermin before 1.220 (20060629) allows remote attackers to read arbitrary files, possibly related to chfn/save.cgi not properly handling an empty shell parameter, which results in changing root"s shell instead of the shell of a specified user.  
Phase
Assigned (20060821)  
Votes
None (candidate not yet proposed)  
Comments