CVE-2006-3392
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 78%
from disclosure to weapon3 days
Published on NVDJul 6
1st PoC+3d
metasploitJun 30
exploitation probability
78%top 1% of all CVEs
observed exploitation
nono source reports it
10 public exploit(s)
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes such as "%01" are removed from the filename. NOTE: This is a different issue than CVE-2006-3274.
Affected products
n/a · n/apublic PoCs found — 10✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/1997exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/2017githubgithub.com/IvanGlinkin/CVE-2006-3392★ 14githubgithub.com/brosck/CVE-2006-3392★ 3githubgithub.com/0xtz/CVE-2006-3392★ 1githubgithub.com/g1vi/CVE-2006-3392★ 1githubgithub.com/kernel-cyber/CVE-2006-3392★ 0githubgithub.com/Adel-kaka-dz/CVE-2006-3392★ 0githubgithub.com/Adel-hx0d/CVE-2006-3392★ 0githubgithub.com/gb21oc/ExploitWebmin★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://attrition.org/pipermail/vim/2006-July/000923.htmlhttp://attrition.org/pipermail/vim/2006-June/000912.htmlhttp://secunia.com/advisories/20892http://secunia.com/advisories/21105http://secunia.com/advisories/21365http://secunia.com/advisories/22556http://security.gentoo.org/glsa/glsa-200608-11.xmlhttp://www.debian.org/security/2006/dsa-1199http://www.kb.cert.org/vuls/id/999601http://www.mandriva.com/security/advisories?name=MDKSA-2006:125http://www.osvdb.org/26772http://www.securityfocus.com/archive/1/439653/100/0/threaded