CVE-2006-3392
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files,...
- Published
- Jul 6, 2006
- Updated
- Aug 7, 2024
- Assigning CNA
- mitre
- Evidence observed
- Jul 9, 2006
Primary CVSS
nvd · CVSS 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:NHigh · next 30 days
- Percentile
- 99.6%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes such as "%01" are removed from the filename. NOTE: This is a different issue than CVE-2006-3274.
Sources
10- CVE-2006-3392Exploit
Webmin < 1.290 / Usermin < 1.220 - Arbitrary File Disclosure (Python3)
- CVE-2006-3392Exploit
It is a simple tool to exploit local file include . vulnerabilities
- CVE-2006-3392Exploit
Python exploit for CVE-2006-3392, a path traversal in Webmin/Usermin allowing arbitrary file read, demonstrated by retrieving /etc/shadow.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.