Usermin / Usermin
13 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2015-2079 | Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argument) form o… | CRITICAL | 9.9 | Apr 28, 2025 |
| CVE-2007-1276 | Multiple cross-site scripting (XSS) vulnerabilities in chooser.cgi in Webmin before 1.330 and Usermin before 1.260 allow remote attackers to inject arbitrary w… | MEDIUM | 4.3 | Mar 5, 2007 |
| CVE-2006-4246 | Usermin before 1.220 (20060629) allows remote attackers to read arbitrary files, possibly related to chfn/save.cgi not properly handling an empty shell paramet… | LOW | 3.6 | Sep 19, 2006 |
| CVE-2006-4542 | Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site sc… | MEDIUM | 6.8 | Sep 5, 2006 |
| CVE-2006-3392 | Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as d… | MEDIUM | 5.0 | Jul 6, 2006 |
| CVE-2005-3042 | miniserv.pl in Webmin before 1.230 and Usermin before 1.160, when "full PAM conversations" is enabled, allows remote attackers to bypass authentication by spoo… | HIGH | 7.5 | Sep 22, 2005 |
| CVE-2005-1177 | Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, with unknown impact. | HIGH | 10.0 | Apr 19, 2005 |
| CVE-2004-1468 | The web mail functionality in Usermin 1.x and Webmin 1.x allows remote attackers to execute arbitrary commands via shell metacharacters in an e-mail message. | HIGH | 7.5 | Feb 13, 2005 |
| CVE-2004-0559 | The maketemp.pl script in Usermin 1.070 and 1.080 allows local users to overwrite arbitrary files at install time via a symlink attack on the /tmp/.usermin dir… | LOW | 2.1 | Sep 24, 2004 |
| CVE-2004-0588 | Cross-site scripting (XSS) vulnerability in the web mail module for Usermin 1.070 allows remote attackers to insert arbitrary HTML and script via e-mail messag… | MEDIUM | 6.8 | Jun 23, 2004 |
| CVE-2004-0583 | The account lockout functionality in (1) Webmin 1.140 and (2) Usermin 1.070 does not parse certain character strings, which allows remote attackers to conduct… | MEDIUM | 5.0 | Jun 23, 2004 |
| CVE-2003-0101 | miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in B… | HIGH | 10.0 | Feb 26, 2003 |
| CVE-2002-0757 | (1) Webmin 0.96 and (2) Usermin 0.90 with password timeouts enabled allow local and possibly remote attackers to bypass authentication and gain privileges via… | HIGH | 7.5 | Jul 26, 2002 |
| CVE-2002-0756 | Cross-site scripting vulnerability in the authentication page for (1) Webmin 0.96 and (2) Usermin 0.90 allows remote attackers to insert script into an error p… | HIGH | 7.5 | Jul 26, 2002 |
Showing 1 to 13 of 13 CVEs