Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes such as "%01" are removed from the filename.
-
Notifications
You must be signed in to change notification settings - Fork 0
kernel-cyber/CVE-2006-3392
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Folders and files
Name | Name | Last commit message | Last commit date | |
---|---|---|---|---|
Repository files navigation
About
Webmin Local File Include (unauthenticated)
Resources
Stars
Watchers
Forks
Releases
No releases published
Packages 0
No packages published