CVE-2006-3392 Scanner
Detects 'Directory Traversal' vulnerability in Webmin and Usermin affects v. Webmin before 1.290 and Usermin before 1.220.
Short Info
Level
Medium
Single Scan
Single Scan
Can be used by
Asset Owner
Estimated Time
15 seconds
Time Interval
30 days
Scan only one
Domain, IPv4, Subdomain
Toolbox
-
Webmin and Usermin are web-based applications used for managing Unix-based systems. The former is primarily intended for system administrators, while the latter is designed for regular users. Both programs offer an intuitive graphical interface for managing users, domains, services, and files. Additionally, they provide tools for managing email, databases, and networking.
CVE-2006-3392 is a vulnerability that affects Webmin and Usermin versions prior to 1.290 and 1.220, respectively. The exploit occurs when the simplify_path function calls before decoding HTML. Hackers can tamper with directory paths using the dot-dot-slash (../) sequences and bypassing the removal of these sequences from filenames with other bytes like "%01."
Exploiting CVE-2006-3392 can lead to unauthorized access and the ability to read arbitrary files. Attackers can scour through sensitive text files, such as passwords and configuration files, to gain access to the entire system. More sinister attacks may involve the injection of malicious content into code files to execute malicious commands.
By using pro features of the s4e.io platform, users can quickly and easily learn about vulnerabilities in their digital assets. With constant updates and monitoring, users can stay informed about potential threats and judiciously safeguard their systems. Taking preventative measures is critical in securing sensitive data and further penetrating corporate defenses.
REFERENCES
- secunia.com: 21365
- security.gentoo.org: GLSA-200608-11
- http://www.webmin.com/changes.html
- securityfocus.com: 20060710 Re: Webmin / Usermin Arbitrary File Disclosure Vulnerability exploit
- secunia.com: 21105
- securityfocus.com: 18744
- securityfocus.com: 20060715 Webmin / Usermin Arbitrary File Disclosure Vulnerability Perl
- securityfocus.com: 20060715 Re: Webmin / Usermin Arbitrary File Disclosure Vulnerability exploit
- kb.cert.org: VU#999601
- debian.org: DSA-1199
- attrition.org: 20060630 Webmin traversal - changelog
- secunia.com: 20892
- mandriva.com: MDKSA-2006:125
- vupen.com: ADV-2006-2612
- securityfocus.com: 20060709 Webmin / Usermin Arbitrary File Disclosure Vulnerability exploit
- osvdb.org: 26772
- secunia.com: 22556
- attrition.org: 20060711 Re: Webmin traversal - changelog