CVE
- Id
- 20646
- CVE No.
- CVE-2006-4542
- Status
- Candidate
- Description
- Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read CGI program source code, list directories, and possibly execute programs.
- Phase
- Assigned (20060905)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
| Id | CVE Id | CVE No. | Reference | Actions |
|---|---|---|---|---|
| 194261 | 20646 | CVE-2006-4542 | MISC:http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/89_e.html | View |
| 194262 | 20646 | CVE-2006-4542 | CONFIRM:http://webmin.com/security.html | View |
| 194263 | 20646 | CVE-2006-4542 | DEBIAN:DSA-1199 | View |
| 194264 | 20646 | CVE-2006-4542 | URL:http://www.debian.org/security/2006/dsa-1199 | View |
| 194265 | 20646 | CVE-2006-4542 | MANDRIVA:MDKSA-2006:170 | View |
| 194266 | 20646 | CVE-2006-4542 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2006:170 | View |
| 194267 | 20646 | CVE-2006-4542 | JVN:JVN#99776858 | View |
| 194268 | 20646 | CVE-2006-4542 | URL:http://jvn.jp/jp/JVN%2399776858/index.html | View |
| 194269 | 20646 | CVE-2006-4542 | BID:19820 | View |
| 194270 | 20646 | CVE-2006-4542 | URL:http://www.securityfocus.com/bid/19820 | View |
| 194271 | 20646 | CVE-2006-4542 | VUPEN:ADV-2006-3424 | View |
| 194272 | 20646 | CVE-2006-4542 | URL:http://www.vupen.com/english/advisories/2006/3424 | View |
| 194273 | 20646 | CVE-2006-4542 | OSVDB:28337 | View |
| 194274 | 20646 | CVE-2006-4542 | URL:http://www.osvdb.org/28337 | View |
| 194275 | 20646 | CVE-2006-4542 | OSVDB:28338 | View |
| 194276 | 20646 | CVE-2006-4542 | URL:http://www.osvdb.org/28338 | View |
| 194277 | 20646 | CVE-2006-4542 | SECTRACK:1016776 | View |
| 194278 | 20646 | CVE-2006-4542 | URL:http://securitytracker.com/id?1016776 | View |
| 194279 | 20646 | CVE-2006-4542 | SECTRACK:1016777 | View |
| 194280 | 20646 | CVE-2006-4542 | URL:http://securitytracker.com/id?1016777 | View |
| 194281 | 20646 | CVE-2006-4542 | SECUNIA:21690 | View |
| 194282 | 20646 | CVE-2006-4542 | URL:http://secunia.com/advisories/21690 | View |
| 194283 | 20646 | CVE-2006-4542 | SECUNIA:22087 | View |
| 194284 | 20646 | CVE-2006-4542 | URL:http://secunia.com/advisories/22087 | View |
| 194285 | 20646 | CVE-2006-4542 | SECUNIA:22114 | View |
| 194286 | 20646 | CVE-2006-4542 | URL:http://secunia.com/advisories/22114 | View |
| 194287 | 20646 | CVE-2006-4542 | SECUNIA:22556 | View |
| 194288 | 20646 | CVE-2006-4542 | URL:http://secunia.com/advisories/22556 | View |
| 194289 | 20646 | CVE-2006-4542 | XF:webmin-usermin-source-disclosure(28699) | View |
Related JVN
| Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 58920 | JVNDB-2006-001186 | ExBB における PHP リモートファイルインクルージョンの脆弱性 | ExBB には、register_globals が有効になっている際、PHP リモートファイルインクルージョンの脆弱性が存在します。 | CVE-2006-4544 | 20646 | 7.5 | http://jvndb.jvn.jp/ja/contents/2006/JVNDB-2006-001186.html | View |