![](/assets/img/cve_300x82_sin_bg.png)
CVE-2006-3392 – Webmin < 1.290 / Usermin < 1.220 - Arbitrary File Disclosure
https://notcve.org/view.php?id=CVE-2006-3392
06 Jul 2006 — Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes such as "%01" are removed from the filename. NOTE: This is a different issue than CVE-2006-3274. Las aplicaciones Webmin antes de su versión 1.290 y Usermin antes de la 1.220 llaman a la función simplify_path antes de decodificar HTML, lo que permite a atacan... • https://packetstorm.news/files/id/180803 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2005-1177
https://notcve.org/view.php?id=CVE-2005-1177
19 Apr 2005 — Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, with unknown impact. • http://securitytracker.com/id?1013723 •