Name | CVE-2006-4542 |
Description | Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read CGI program source code, list directories, and possibly execute programs. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-1199-1 |
Debian Bugs | 391284 |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
usermin | source | (unstable) | (unfixed) | |||
webmin | source | sarge | 1.180-3sarge1 | DSA-1199-1 | ||
webmin | source | (unstable) | (unfixed) | 391284 |