Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
webmin usermin vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2008-0720
Cross-site scripting (XSS) vulnerability in Webmin 1.370 and 1.390 and Usermin 1.300 and 1.320 allows remote malicious users to inject arbitrary web script or HTML via the search parameter to webmin_search.cgi (aka the search section), and possibly other components accessed throu...
Webmin Usermin 1.32
Webmin Webmin 1.370
Webmin Usermin 1.3
Webmin Webmin 1.390
4.3
CVSSv2
CVE-2007-3156
Multiple cross-site scripting (XSS) vulnerabilities in pam_login.cgi in Webmin prior to 1.350 and Usermin prior to 1.280 allow remote malicious users to inject arbitrary web script or HTML via the (1) cid, (2) message, or (3) question parameter. NOTE: some of these details are ob...
Webmin Usermin
Webmin Webmin
4.3
CVSSv2
CVE-2007-1276
Multiple cross-site scripting (XSS) vulnerabilities in chooser.cgi in Webmin prior to 1.330 and Usermin prior to 1.260 allow remote malicious users to inject arbitrary web script or HTML via a crafted filename.
Usermin Usermin 1.040
Usermin Usermin 1.051
Usermin Usermin 1.120
Usermin Usermin 1.130
Webmin Webmin 1.0.00
Webmin Webmin 1.0.10
Webmin Webmin 1.0.70
Webmin Webmin 1.0.80
Webmin Webmin 1.1.40
Webmin Webmin 1.1.50
Webmin Webmin 1.2.20
Usermin Usermin 1.020
Usermin Usermin 1.030
Usermin Usermin 1.100
Usermin Usermin 1.110
Usermin Usermin 1.240
Usermin Usermin 1.250
Webmin Webmin 1.0.51
Webmin Webmin 1.0.60
Webmin Webmin 1.1.21
Webmin Webmin 1.1.30
Usermin Usermin 1.060
6.8
CVSSv2
CVE-2006-4542
Webmin prior to 1.296 and Usermin prior to 1.226 do not properly handle a URL with a null ("%00") character, which allows remote malicious users to conduct cross-site scripting (XSS), read CGI program source code, list directories, and possibly execute programs.
Usermin Usermin 0.7
Usermin Usermin 0.4
Usermin Usermin 0.92
Usermin Usermin 0.93
Usermin Usermin 0.94
Usermin Usermin 1.010
Usermin Usermin 1.020
Usermin Usermin 1.090
Usermin Usermin 1.100
Webmin Webmin 0.1
Webmin Webmin 0.2
Webmin Webmin 0.21
Webmin Webmin 0.5
Webmin Webmin 0.51
Webmin Webmin 0.80
Webmin Webmin 0.83
Webmin Webmin 0.93
Webmin Webmin 0.94
Webmin Webmin 1.0.10
Webmin Webmin 1.0.20
Webmin Webmin 1.0.80
Webmin Webmin 1.0.90
5
CVSSv2
CVE-2006-3392
Webmin prior to 1.290 and Usermin prior to 1.220 calls the simplify_path function before decoding HTML, which allows remote malicious users to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before byt...
Webmin Webmin
Usermin Usermin
2 EDB exploits
2 Nmap scripts
7 Github repositories
7.5
CVSSv2
CVE-2005-3912
Format string vulnerability in miniserv.pl Perl web server in Webmin prior to 1.250 and Usermin prior to 1.180, with syslog logging enabled, allows remote malicious users to cause a denial of service (crash or memory consumption) and possibly execute arbitrary code via format str...
Webmin Webmin
Debian Debian Linux 3.1
7.5
CVSSv2
CVE-2005-3042
miniserv.pl in Webmin prior to 1.230 and Usermin prior to 1.160, when "full PAM conversations" is enabled, allows remote malicious users to bypass authentication by spoofing session IDs via certain metacharacters (line feed or carriage return).
Webmin Webmin 1.2.20
Usermin Usermin 1.150
10
CVSSv2
CVE-2005-1177
Unknown vulnerability in (1) Webmin and (2) Usermin prior to 1.200 causes Webmin to change permissions and ownership of configuration files, with unknown impact.
Usermin Usermin 0.8
Usermin Usermin 0.9
Usermin Usermin 0.98
Usermin Usermin 0.99
Usermin Usermin 1.060
Usermin Usermin 1.070
Usermin Usermin 1.140
Webmin Webmin 0.4
Webmin Webmin 0.93
Webmin Webmin 0.94
Webmin Webmin 1.0.10
Webmin Webmin 1.0.20
Webmin Webmin 1.0.90
Webmin Webmin 1.1.00
Usermin Usermin 0.4
Usermin Usermin 0.5
Usermin Usermin 0.93
Usermin Usermin 0.94
Usermin Usermin 1.020
Usermin Usermin 1.030
Usermin Usermin 1.100
Usermin Usermin 1.110
7.5
CVSSv2
CVE-2004-1468
The web mail functionality in Usermin 1.x and Webmin 1.x allows remote malicious users to execute arbitrary commands via shell metacharacters in an e-mail message.
Usermin Usermin 1.000
Usermin Usermin 1.080
Webmin Webmin 1.0.00
Webmin Webmin 1.1.00
Webmin Webmin 1.1.10
Usermin Usermin 1.030
Usermin Usermin 1.040
Webmin Webmin 1.0.60
Webmin Webmin 1.0.70
Webmin Webmin 1.1.40
Webmin Webmin 1.1.50
Usermin Usermin 1.010
Usermin Usermin 1.020
Webmin Webmin 1.0.20
Webmin Webmin 1.0.50
Webmin Webmin 1.1.21
Webmin Webmin 1.1.30
Usermin Usermin 1.051
Usermin Usermin 1.060
Usermin Usermin 1.070
Webmin Webmin 1.0.80
Webmin Webmin 1.0.90
2.1
CVSSv2
CVE-2004-0559
The maketemp.pl script in Usermin 1.070 and 1.080 allows local users to overwrite arbitrary files at install time via a symlink attack on the /tmp/.usermin directory.
Usermin Usermin 1.060
Usermin Usermin 1.070
Webmin Webmin 1.0.80
Webmin Webmin 1.0.90
Usermin Usermin 1.020
Usermin Usermin 1.030
Webmin Webmin 1.0.20
Webmin Webmin 1.0.50
Webmin Webmin 1.1.21
Webmin Webmin 1.1.30
Usermin Usermin 1.000
Usermin Usermin 1.010
Usermin Usermin 1.080
Webmin Webmin 1.0.00
Webmin Webmin 1.1.00
Webmin Webmin 1.1.10
Usermin Usermin 1.040
Usermin Usermin 1.051
Webmin Webmin 1.0.60
Webmin Webmin 1.0.70
Webmin Webmin 1.1.40
Webmin Webmin 1.1.50
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-32976
CVE-2024-33557
CVE-2024-36801
CVE-2024-35654
authentication bypass
CVE-2024-24919
CSRF
code execution
CVE-2024-27348
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »