Page 2 of 11 results (0.000 seconds)

CVSS: 7.5EPSS: 71%CPEs: 2EXPL: 11

06 Jul 2006 — Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes such as "%01" are removed from the filename. NOTE: This is a different issue than CVE-2006-3274. Las aplicaciones Webmin antes de su versión 1.290 y Usermin antes de la 1.220 llaman a la función simplify_path antes de decodificar HTML, lo que permite a atacan... • https://packetstorm.news/files/id/180803 •