← Back

CVE-2007-1276

nvd nist
Published: Mar 5, 2007Modified: Apr 23, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in chooser.cgi in Webmin before 1.330 and Usermin before 1.260 allow remote attackers to inject arbitrary web script or HTML via a crafted filename.

Affected (44)

Products: Usermin: Usermin · Webmin: Webmin
1 product
Usermin
1 product
Webmin
Configuration A
44 vulnerable
Vulnerable SoftwareAffected Versions
Usermin
Version 1.000
Version 1.010
Version 1.020
Version 1.030
Version 1.040
Version 1.051
Version 1.060
Version 1.070
Version 1.080
Version 1.090
Version 1.100
Version 1.110
Version 1.120
Version 1.130
Version 1.140
Version 1.150
Version 1.210
Version 1.220
Version 1.230
Version 1.240
Version 1.250
Webmin
Version 1.0.00
Version 1.0.10
Version 1.0.20
Version 1.0.30
Version 1.0.40
Version 1.0.50
Version 1.0.51
Version 1.0.60
Version 1.0.70
Version 1.0.80
Version 1.0.90
Version 1.1.00
Version 1.1.10
Version 1.1.20
Version 1.1.21
Version 1.1.30
Version 1.1.40
Version 1.1.50
Version 1.2.20
Version 1.2.30
Version 1.2.40
Version 1.2.50
Version 1.3.20

References (14)

Source: cve@mitre.org
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.