Записи Usermin
13 опубликованных записей вендора usermin.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 7,7 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 46,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
45В плане | CVE-2003-0101Proof of concept | miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage usermin · usermin | Критическая10,0 | — | 15,5 % | 3 мар. 2003 г. |
43В плане | CVE-2006-3392Готовый эксплойт | Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arusermin · usermin | Средняя5,0 | — | 78,3 % | 6 июл. 2006 г. |
41В плане | CVE-2005-1177Эксплойта нет | Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, wusermin · usermin | Критическая10,0 | — | 1,8 % | 2 мая 2005 г. |
31Наблюдать | CVE-2005-3042Эксплойта нет | miniserv.pl in Webmin before 1.230 and Usermin before 1.160, when "full PAM conversations" is enabled, allows remote attackers to bypass autusermin · usermin | Высокая7,5 | — | 4,1 % | 22 сент. 2005 г. |
31Наблюдать | CVE-2004-1468Эксплойта нет | The web mail functionality in Usermin 1.x and Webmin 1.x allows remote attackers to execute arbitrary commands via shell metacharacters in ausermin · usermin | Высокая7,5 | — | 3,6 % | 31 дек. 2004 г. |
31Наблюдать | CVE-2002-0757Эксплойта нет | (1) Webmin 0.96 and (2) Usermin 0.90 with password timeouts enabled allow local and possibly remote attackers to bypass authentication and gusermin · usermin | Высокая7,5 | — | 1,9 % | 12 авг. 2002 г. |
31Наблюдать | CVE-2002-0756Эксплойта нет | Cross-site scripting vulnerability in the authentication page for (1) Webmin 0.96 and (2) Usermin 0.90 allows remote attackers to insert scrusermin · usermin | Высокая7,5 | — | 1,7 % | 12 авг. 2002 г. |
28Наблюдать | CVE-2006-4542Эксплойта нет | Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to cousermin · usermin · CWE-79 | Средняя6,8 | — | 3,2 % | 5 сент. 2006 г. |
27Наблюдать | CVE-2004-0588Эксплойта нет | Cross-site scripting (XSS) vulnerability in the web mail module for Usermin 1.070 allows remote attackers to insert arbitrary HTML and scripusermin · usermin | Средняя6,8 | — | 1,4 % | 6 авг. 2004 г. |
21Наблюдать | CVE-2004-0583Эксплойта нет | The account lockout functionality in (1) Webmin 1.140 and (2) Usermin 1.070 does not parse certain character strings, which allows remote atusermin · usermin | Средняя5,0 | — | 2,1 % | 6 авг. 2004 г. |
17Наблюдать | CVE-2007-1276Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in chooser.cgi in Webmin before 1.330 and Usermin before 1.260 allow remote attackers tousermin · usermin · CWE-352 | Средняя4,3 | — | 0,6 % | 5 мар. 2007 г. |
14Наблюдать | CVE-2006-4246Эксплойта нет | Usermin before 1.220 (20060629) allows remote attackers to read arbitrary files, possibly related to chfn/save.cgi not properly handling an usermin · usermin | Низкая3,6 | — | 0,9 % | 19 сент. 2006 г. |
8Наблюдать | CVE-2004-0559Эксплойта нет | The maketemp.pl script in Usermin 1.070 and 1.080 allows local users to overwrite arbitrary files at install time via a symlink attack on thusermin · usermin | Низкая2,1 | — | 0,4 % | 20 окт. 2004 г. |
- CVE-2003-010145В плане
miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage
КритическаяCVSS 10,0Proof of conceptEPSS 15 %usermin · usermin3 мар. 2003 г.
- CVE-2006-339243В плане
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read ar
СредняяCVSS 5,0Готовый эксплойтEPSS 78 %usermin · usermin6 июл. 2006 г.
- CVE-2005-117741В плане
Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, w
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %usermin · usermin2 мая 2005 г.
- CVE-2005-304231Наблюдать
miniserv.pl in Webmin before 1.230 and Usermin before 1.160, when "full PAM conversations" is enabled, allows remote attackers to bypass aut
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %usermin · usermin22 сент. 2005 г.
- CVE-2004-146831Наблюдать
The web mail functionality in Usermin 1.x and Webmin 1.x allows remote attackers to execute arbitrary commands via shell metacharacters in a
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %usermin · usermin31 дек. 2004 г.
- CVE-2002-075731Наблюдать
(1) Webmin 0.96 and (2) Usermin 0.90 with password timeouts enabled allow local and possibly remote attackers to bypass authentication and g
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %usermin · usermin12 авг. 2002 г.
- CVE-2002-075631Наблюдать
Cross-site scripting vulnerability in the authentication page for (1) Webmin 0.96 and (2) Usermin 0.90 allows remote attackers to insert scr
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %usermin · usermin12 авг. 2002 г.
- CVE-2006-454228Наблюдать
Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to co
СредняяCVSS 6,8Эксплойта нетEPSS 3 %usermin · usermin5 сент. 2006 г.
- CVE-2004-058827Наблюдать
Cross-site scripting (XSS) vulnerability in the web mail module for Usermin 1.070 allows remote attackers to insert arbitrary HTML and scrip
СредняяCVSS 6,8Эксплойта нетEPSS 1 %usermin · usermin6 авг. 2004 г.
- CVE-2004-058321Наблюдать
The account lockout functionality in (1) Webmin 1.140 and (2) Usermin 1.070 does not parse certain character strings, which allows remote at
СредняяCVSS 5,0Эксплойта нетEPSS 2 %usermin · usermin6 авг. 2004 г.
- CVE-2007-127617Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in chooser.cgi in Webmin before 1.330 and Usermin before 1.260 allow remote attackers to
СредняяCVSS 4,3Эксплойта нетEPSS 1 %usermin · usermin5 мар. 2007 г.
- CVE-2006-424614Наблюдать
Usermin before 1.220 (20060629) allows remote attackers to read arbitrary files, possibly related to chfn/save.cgi not properly handling an
НизкаяCVSS 3,6Эксплойта нетEPSS 1 %usermin · usermin19 сент. 2006 г.
- CVE-2004-05598Наблюдать
The maketemp.pl script in Usermin 1.070 and 1.080 allows local users to overwrite arbitrary files at install time via a symlink attack on th
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %usermin · usermin20 окт. 2004 г.