Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Usermin MEDIUM 6.8
CVE-2006-4542

Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cro…

Fix: after 1.220
Fix from $1,600 2006-09-05
Usermin MEDIUM 5.0
CVE-2006-3392EPSS 78%

Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary f…

Fix: after 1.210
Fix from $1,600 2006-07-06
Usermin HIGH 7.5
CVE-2005-3042

miniserv.pl in Webmin before 1.230 and Usermin before 1.160, when "full PAM conversations" is enabled, allows remote attackers to bypass authenticati…

Patch available
Fix from $1,950 2005-09-22
Usermin HIGH 10.0
CVE-2005-1177

Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, with unkno…

Patch available
Fix from $1,950 2005-05-02
Usermin HIGH 7.5
CVE-2004-1468

The web mail functionality in Usermin 1.x and Webmin 1.x allows remote attackers to execute arbitrary commands via shell metacharacters in an e-mail …

Patch available
Fix from $1,950 2004-12-31
Usermin MEDIUM 6.8
CVE-2004-0588

Cross-site scripting (XSS) vulnerability in the web mail module for Usermin 1.070 allows remote attackers to insert arbitrary HTML and script via e-m…

Patch available
Fix from $1,600 2004-08-06
Usermin HIGH 7.5
CVE-2002-0756

Cross-site scripting vulnerability in the authentication page for (1) Webmin 0.96 and (2) Usermin 0.90 allows remote attackers to insert script into …

Patch available
Fix from $1,950 2002-08-12
Usermin HIGH 7.5
CVE-2002-0757

(1) Webmin 0.96 and (2) Usermin 0.90 with password timeouts enabled allow local and possibly remote attackers to bypass authentication and gain privi…

Patch available
Fix from $1,950 2002-08-12