← back
CVE-2006-3392

CVE-2006-3392

60Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 78%
from disclosure to weapon3 days
Published on NVDJul 6
1st PoC+3d
metasploitJun 30
exploitation probability
78%top 1% of all CVEs
observed exploitation
nono source reports it
10 public exploit(s)
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes such as "%01" are removed from the filename. NOTE: This is a different issue than CVE-2006-3274.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.