← Back

CVE-2006-4246

nvd nist
Published: Sep 19, 2006Modified: Apr 16, 2026

JSON object

Loading...
3.6
Vector
AV:L/AC:L/Au:N/C:P/I:N/A:P
Exploitability: 3.9 / Impact: 4.9
Source: NVD

Description

Usermin before 1.220 (20060629) allows remote attackers to read arbitrary files, possibly related to chfn/save.cgi not properly handling an empty shell parameter, which results in changing root's shell instead of the shell of a specified user.

Affected (32)

Products: Usermin: Usermin
1 product
Usermin
Configuration A
32 vulnerable
Vulnerable SoftwareAffected Versions
Usermin
Up to 1.210
Version 0.4
Version 0.5
Version 0.6
Version 0.7
Version 0.8
Version 0.91
Version 0.92
Version 0.93
Version 0.94
Version 0.95
Version 0.96
Version 0.97
Version 0.98
Version 0.99
Version 0.9
Version 1.000
Version 1.010
Version 1.020
Version 1.030
Version 1.040
Version 1.051
Version 1.060
Version 1.070
Version 1.080
Version 1.090
Version 1.100
Version 1.110
Version 1.120
Version 1.130
Version 1.140
Version 1.150

References (18)

Source: security@debian.org
Vendor Advisory
Source: security@debian.org
PatchVendor Advisory
Source: security@debian.org
Patch
Source: security@debian.org
Patch
Source: security@debian.org
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.