← Back

CVE-2006-4542

nvd nist
Published: Sep 5, 2006Modified: Apr 16, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read CGI program source code, list directories, and possibly execute programs.

Affected (92)

Products: Usermin: Usermin · Webmin: Webmin
1 product
Usermin
1 product
Webmin
Configuration A
92 vulnerable
Vulnerable SoftwareAffected Versions
Usermin
Up to 1.220
Version 0.4
Version 0.5
Version 0.6
Version 0.7
Version 0.8
Version 0.91
Version 0.92
Version 0.93
Version 0.94
Version 0.95
Version 0.96
Version 0.97
Version 0.98
Version 0.99
Version 0.9
Version 1.000
Version 1.010
Version 1.020
Version 1.030
Version 1.040
Version 1.051
Version 1.060
Version 1.070
Version 1.080
Version 1.090
Version 1.100
Version 1.110
Version 1.120
Version 1.130
Version 1.140
Version 1.150
Version 1.210
Webmin
Up to 1.2.90
Version 0.1
Version 0.21
Version 0.22
Version 0.2
Version 0.31
Version 0.3
Version 0.41
Version 0.42
Version 0.4
Version 0.51
Version 0.5
Version 0.6
Version 0.76
Version 0.77
Version 0.78
Version 0.79
Version 0.7
Version 0.80
Version 0.83
Version 0.84
Version 0.85
Version 0.88
Version 0.90
Version 0.91
Version 0.92.1
Version 0.92
Version 0.93
Version 0.94
Version 0.95
Version 0.96
Version 0.97
Version 0.98
Version 0.99
Version 1.0.00
Version 1.0.10
Version 1.0.20
Version 1.0.30
Version 1.0.40
Version 1.0.50
Version 1.0.51
Version 1.0.60
Version 1.0.70
Version 1.0.80
Version 1.0.90
Version 1.1.00
Version 1.1.10
Version 1.1.20
Version 1.1.21
Version 1.1.30
Version 1.1.40
Version 1.1.50
Version 1.2.20
Version 1.2.30
Version 1.2.40
Version 1.2.50
Version 1.2.60
Version 1.2.70
Version 1.2.80

References (32)

Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
Patch
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.