Usermin kayıtları
usermin üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %7,7
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %46,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
45Planlayın | CVE-2003-0101Kavram kanıtı | miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage usermin · usermin | Kritik10,0 | — | %15,5 | 3 Mar 2003 |
43Planlayın | CVE-2006-3392Silahlaştırılmış | Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arusermin · usermin | Orta5,0 | — | %78,3 | 6 Tem 2006 |
41Planlayın | CVE-2005-1177İstismar yok | Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, wusermin · usermin | Kritik10,0 | — | %1,8 | 2 May 2005 |
31İzleyin | CVE-2005-3042İstismar yok | miniserv.pl in Webmin before 1.230 and Usermin before 1.160, when "full PAM conversations" is enabled, allows remote attackers to bypass autusermin · usermin | Yüksek7,5 | — | %4,1 | 22 Eyl 2005 |
31İzleyin | CVE-2004-1468İstismar yok | The web mail functionality in Usermin 1.x and Webmin 1.x allows remote attackers to execute arbitrary commands via shell metacharacters in ausermin · usermin | Yüksek7,5 | — | %3,6 | 31 Ara 2004 |
31İzleyin | CVE-2002-0757İstismar yok | (1) Webmin 0.96 and (2) Usermin 0.90 with password timeouts enabled allow local and possibly remote attackers to bypass authentication and gusermin · usermin | Yüksek7,5 | — | %1,9 | 12 Ağu 2002 |
31İzleyin | CVE-2002-0756İstismar yok | Cross-site scripting vulnerability in the authentication page for (1) Webmin 0.96 and (2) Usermin 0.90 allows remote attackers to insert scrusermin · usermin | Yüksek7,5 | — | %1,7 | 12 Ağu 2002 |
28İzleyin | CVE-2006-4542İstismar yok | Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to cousermin · usermin · CWE-79 | Orta6,8 | — | %3,2 | 5 Eyl 2006 |
27İzleyin | CVE-2004-0588İstismar yok | Cross-site scripting (XSS) vulnerability in the web mail module for Usermin 1.070 allows remote attackers to insert arbitrary HTML and scripusermin · usermin | Orta6,8 | — | %1,4 | 6 Ağu 2004 |
21İzleyin | CVE-2004-0583İstismar yok | The account lockout functionality in (1) Webmin 1.140 and (2) Usermin 1.070 does not parse certain character strings, which allows remote atusermin · usermin | Orta5,0 | — | %2,1 | 6 Ağu 2004 |
17İzleyin | CVE-2007-1276İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in chooser.cgi in Webmin before 1.330 and Usermin before 1.260 allow remote attackers tousermin · usermin · CWE-352 | Orta4,3 | — | %0,6 | 5 Mar 2007 |
14İzleyin | CVE-2006-4246İstismar yok | Usermin before 1.220 (20060629) allows remote attackers to read arbitrary files, possibly related to chfn/save.cgi not properly handling an usermin · usermin | Düşük3,6 | — | %0,9 | 19 Eyl 2006 |
8İzleyin | CVE-2004-0559İstismar yok | The maketemp.pl script in Usermin 1.070 and 1.080 allows local users to overwrite arbitrary files at install time via a symlink attack on thusermin · usermin | Düşük2,1 | — | %0,4 | 20 Eki 2004 |
- CVE-2003-010145Planlayın
miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage
KritikCVSS 10,0Kavram kanıtıEPSS %15usermin · usermin3 Mar 2003
- CVE-2006-339243Planlayın
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read ar
OrtaCVSS 5,0SilahlaştırılmışEPSS %78usermin · usermin6 Tem 2006
- CVE-2005-117741Planlayın
Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, w
KritikCVSS 10,0İstismar yokEPSS %2usermin · usermin2 May 2005
- CVE-2005-304231İzleyin
miniserv.pl in Webmin before 1.230 and Usermin before 1.160, when "full PAM conversations" is enabled, allows remote attackers to bypass aut
YüksekCVSS 7,5İstismar yokEPSS %4usermin · usermin22 Eyl 2005
- CVE-2004-146831İzleyin
The web mail functionality in Usermin 1.x and Webmin 1.x allows remote attackers to execute arbitrary commands via shell metacharacters in a
YüksekCVSS 7,5İstismar yokEPSS %4usermin · usermin31 Ara 2004
- CVE-2002-075731İzleyin
(1) Webmin 0.96 and (2) Usermin 0.90 with password timeouts enabled allow local and possibly remote attackers to bypass authentication and g
YüksekCVSS 7,5İstismar yokEPSS %2usermin · usermin12 Ağu 2002
- CVE-2002-075631İzleyin
Cross-site scripting vulnerability in the authentication page for (1) Webmin 0.96 and (2) Usermin 0.90 allows remote attackers to insert scr
YüksekCVSS 7,5İstismar yokEPSS %2usermin · usermin12 Ağu 2002
- CVE-2006-454228İzleyin
Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to co
OrtaCVSS 6,8İstismar yokEPSS %3usermin · usermin5 Eyl 2006
- CVE-2004-058827İzleyin
Cross-site scripting (XSS) vulnerability in the web mail module for Usermin 1.070 allows remote attackers to insert arbitrary HTML and scrip
OrtaCVSS 6,8İstismar yokEPSS %1usermin · usermin6 Ağu 2004
- CVE-2004-058321İzleyin
The account lockout functionality in (1) Webmin 1.140 and (2) Usermin 1.070 does not parse certain character strings, which allows remote at
OrtaCVSS 5,0İstismar yokEPSS %2usermin · usermin6 Ağu 2004
- CVE-2007-127617İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in chooser.cgi in Webmin before 1.330 and Usermin before 1.260 allow remote attackers to
OrtaCVSS 4,3İstismar yokEPSS %1usermin · usermin5 Mar 2007
- CVE-2006-424614İzleyin
Usermin before 1.220 (20060629) allows remote attackers to read arbitrary files, possibly related to chfn/save.cgi not properly handling an
DüşükCVSS 3,6İstismar yokEPSS %1usermin · usermin19 Eyl 2006
- CVE-2004-05598İzleyin
The maketemp.pl script in Usermin 1.070 and 1.080 allows local users to overwrite arbitrary files at install time via a symlink attack on th
DüşükCVSS 2,1İstismar yokEPSS %0usermin · usermin20 Eki 2004