|
|
| |
|
| |
webmin: cross-site scripting
| Package(s): | webmin |
CVE #(s): | CVE-2006-4542
|
| Created: | September 26, 2006 |
Updated: | October 24, 2006 |
| Description: |
Webmin before 1.296 and Usermin before 1.226 does not properly handle a URL
with a null ("%00") character, which allows remote attackers to conduct
cross-site scripting (XSS), read CGI program source code, list directories,
and possibly execute programs. |
| Alerts: |
|
( Log in to post comments)
|
|
|