>> Webmin and Usermin Unspecified Parameter Arbitrary File Disclosure Vulnerability
Title : Webmin and Usermin Unspecified Parameter Arbitrary File Disclosure Vulnerability VUPEN ID : VUPEN/ADV-2006-2612 CVE ID : CVE-2006-3392
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-06-30
Technical Description
A vulnerability has been identified in Webmin and Usermin, which could be exploited by remote attackers to gain access to arbitrary files on a vulnerable system. This flaw is due to an input validation error when handling a malformed URL, which could be exploited by remote unauthenticated attackers to access and read the contents of arbitrary files on an affected system.