Перейти к содержимому
Noroxi

Записи Usermin

13 опубликованных записей вендора usermin.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
1 · 7,7 %
Pre-auth RCE
1
С записью об исправлении
46,2 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

    Столбик: всего · тёмная часть: CISA KEV.

    Повторяющиеся классы

    Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

    CWE

    Все записи

    13 записей
    • CVE-2003-0101
      45В плане

      miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage

      КритическаяCVSS 10,0Proof of conceptEPSS 15 %

      usermin · usermin3 мар. 2003 г.

    • CVE-2006-3392
      43В плане

      Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read ar

      СредняяCVSS 5,0Готовый эксплойтEPSS 78 %

      usermin · usermin6 июл. 2006 г.

    • CVE-2005-1177
      41В плане

      Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, w

      КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

      usermin · usermin2 мая 2005 г.

    • CVE-2005-3042
      31Наблюдать

      miniserv.pl in Webmin before 1.230 and Usermin before 1.160, when "full PAM conversations" is enabled, allows remote attackers to bypass aut

      ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %

      usermin · usermin22 сент. 2005 г.

    • CVE-2004-1468
      31Наблюдать

      The web mail functionality in Usermin 1.x and Webmin 1.x allows remote attackers to execute arbitrary commands via shell metacharacters in a

      ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %

      usermin · usermin31 дек. 2004 г.

    • CVE-2002-0757
      31Наблюдать

      (1) Webmin 0.96 and (2) Usermin 0.90 with password timeouts enabled allow local and possibly remote attackers to bypass authentication and g

      ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

      usermin · usermin12 авг. 2002 г.

    • CVE-2002-0756
      31Наблюдать

      Cross-site scripting vulnerability in the authentication page for (1) Webmin 0.96 and (2) Usermin 0.90 allows remote attackers to insert scr

      ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

      usermin · usermin12 авг. 2002 г.

    • CVE-2006-4542
      28Наблюдать

      Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to co

      СредняяCVSS 6,8Эксплойта нетEPSS 3 %

      usermin · usermin5 сент. 2006 г.

    • CVE-2004-0588
      27Наблюдать

      Cross-site scripting (XSS) vulnerability in the web mail module for Usermin 1.070 allows remote attackers to insert arbitrary HTML and scrip

      СредняяCVSS 6,8Эксплойта нетEPSS 1 %

      usermin · usermin6 авг. 2004 г.

    • CVE-2004-0583
      21Наблюдать

      The account lockout functionality in (1) Webmin 1.140 and (2) Usermin 1.070 does not parse certain character strings, which allows remote at

      СредняяCVSS 5,0Эксплойта нетEPSS 2 %

      usermin · usermin6 авг. 2004 г.

    • CVE-2007-1276
      17Наблюдать

      Multiple cross-site scripting (XSS) vulnerabilities in chooser.cgi in Webmin before 1.330 and Usermin before 1.260 allow remote attackers to

      СредняяCVSS 4,3Эксплойта нетEPSS 1 %

      usermin · usermin5 мар. 2007 г.

    • CVE-2006-4246
      14Наблюдать

      Usermin before 1.220 (20060629) allows remote attackers to read arbitrary files, possibly related to chfn/save.cgi not properly handling an

      НизкаяCVSS 3,6Эксплойта нетEPSS 1 %

      usermin · usermin19 сент. 2006 г.

    • CVE-2004-0559
      8Наблюдать

      The maketemp.pl script in Usermin 1.070 and 1.080 allows local users to overwrite arbitrary files at install time via a symlink attack on th

      НизкаяCVSS 2,1Эксплойта нетEPSS 0 %

      usermin · usermin20 окт. 2004 г.