CVE-2006-4542

Publication date 5 September 2006

Last updated 17 July 2025


Ubuntu priority

Description

Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read CGI program source code, list directories, and possibly execute programs.

Status

Package Ubuntu Release Status
usermin 7.04 feisty Not in release
6.10 edgy Not in release
6.06 LTS dapper Not in release


Access our resources on patching vulnerabilities