MEDIUM · 6.8

CVE-2006-4542

Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read CGI program source co...

Vulnerability Description

Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read CGI program source code, list directories, and possibly execute programs.

CVSS Score

6.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
UserminUsermin<= 1.220
WebminWebmin<= 1.2.90

Related Weaknesses (CWE)

References

FAQ

What is CVE-2006-4542?

CVE-2006-4542 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read CGI program source co...

How severe is CVE-2006-4542?

CVE-2006-4542 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-4542?

Check the references section above for vendor advisories and patch information. Affected products include: Usermin Usermin, Webmin Webmin.