CVE-2014-3886
https://notcve.org/view.php?id=CVE-2014-3886
Cross-site scripting (XSS) vulnerability in Webmin before 1.690, when referrer checking is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this might overlap CVE-2014-3924. Vulnerabilidad de XSS en Webmin anterior a 1.690, cuando la comprobación de referenciadores está deshabilitada, permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados. NOTA: esto podría solaparse con CVE-2014-3924. • http://jvn.jp/en/jp/JVN02213197/index.html http://jvndb.jvn.jp/jvndb/JVNDB-2014-000060 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2014-3884
https://notcve.org/view.php?id=CVE-2014-3884
Cross-site scripting (XSS) vulnerability in Usermin before 1.600 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this might overlap CVE-2014-3924. Vulnerabilidad de XSS en Usermin anterior a 1.600 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados. NOTA: esto podría solarse con CVE-2014-3924. • http://jvn.jp/en/jp/JVN92737498/index.html http://jvndb.jvn.jp/jvndb/JVNDB-2014-000058 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2014-3883
https://notcve.org/view.php?id=CVE-2014-3883
Usermin before 1.600 allows remote attackers to execute arbitrary operating-system commands via unspecified vectors related to a user action. Usermin anterior a 1.600 permite a atacantes remotos ejecutar comandos arbitrarios del sistema operativo a través de vectores no especificados relacionados con una acción del usuario. • http://jvn.jp/en/jp/JVN48805624/index.html http://jvndb.jvn.jp/jvndb/JVNDB-2014-000057 https://www.ipa.go.jp/security/ciadr/vul/20140620-jvn.html • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2014-3924
https://notcve.org/view.php?id=CVE-2014-3924
Multiple cross-site scripting (XSS) vulnerabilities in Webmin before 1.690 and Usermin before 1.600 allow remote attackers to inject arbitrary web script or HTML via vectors related to popup windows. Múltiples vulnerabilidades de XSS en Webmin anterior a 1.690 y Usermin anterior a 1.600 permiten a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de vectores relacionados con ventanas emergentes. • http://secunia.com/advisories/58917 http://secunia.com/advisories/58919 http://www.securityfocus.com/bid/67647 http://www.securityfocus.com/bid/67649 http://www.securitytracker.com/id/1030296 http://www.securitytracker.com/id/1030297 http://www.webmin.com/changes.html http://www.webmin.com/uchanges.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2014-0339
https://notcve.org/view.php?id=CVE-2014-0339
Cross-site scripting (XSS) vulnerability in view.cgi in Webmin before 1.680 allows remote attackers to inject arbitrary web script or HTML via the search parameter. Vulnerabilidad de XSS en view.cgi en Webmin anterior a 1.680 permite a atacantes remotos inyectar script Web o HTML arbitrarios a través del parámetro search. • http://seclists.org/fulldisclosure/2014/Mar/274 http://www-01.ibm.com/support/docview.wss?uid=swg21679713 http://www.kb.cert.org/vuls/id/381692 http://www.securityfocus.com/bid/66248 http://www.webmin.com/changes.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •