Products: 1
    Vulnerabilities: 13
    Known Exploited: 0
    2
    Critical Level Threats
    4
    High Level Threats
    5
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2007-1276

    Multiple cross-site scripting (XSS) vulnerabilities in chooser.cgi in Webmin before 1.330 and Usermin before 1.260 allow remote attackers to inject arbitrary web script or HTML via a crafted filename.

    Last Modified: Apr 23, 2026
    Published: Mar 05, 2007

    CVE-2006-4246

    Usermin before 1.220 (20060629) allows remote attackers to read arbitrary files, possibly related to chfn/save.cgi not properly handling an empty shell parameter, which results in changing root's shell instead of the shell of a specified user.

    Last Modified: Apr 16, 2026
    Published: Sep 19, 2006

    CVE-2006-4542

    Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read CGI program source code, list directories, and possibly execute programs.

    Last Modified: Apr 16, 2026
    Published: Sep 05, 2006

    CVE-2006-3392

    Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes such as "%01" are removed from the filename. NOTE: This is a different issue than CVE-2006-3274.

    Last Modified: Apr 16, 2026
    Published: Jul 06, 2006

    CVE-2005-3042

    miniserv.pl in Webmin before 1.230 and Usermin before 1.160, when "full PAM conversations" is enabled, allows remote attackers to bypass authentication by spoofing session IDs via certain metacharacters (line feed or carriage return).

    Last Modified: Apr 16, 2026
    Published: Sep 22, 2005
    Items Per Page
    Usermin Vulnerabilities & Security CVEs | CVE-DB