OSVDB ID: 28337

Title: Webmin/Usermin NULL Character Unspecified Source Disclosure

Info

Disclosure

Sep 01, 2006

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

Webmin/Usermin contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered because input passed in a NULL character is not properly verified, this will disclose the source code of arbitrary CGI and Perl programs resulting in a loss of confidentiality.

Classification

Location: Remote / Network Access
Attack Type: Information Disclosure
Impact: Loss of Confidentiality
Exploit: Exploit Unknown
OSVDB: Web Related

Solution

Upgrade to version 1.296 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Webmin

Webmin

1.290

Usermin

1.220

References

Credit

  • Keigo Yamazaki - Little eArth Corporation


Direct URL: http://osvdb.org/36218