Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r78v-6mh4-m4rm

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read CGI program source code, list directories, and possibly execute programs.

Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read CGI program source code, list directories, and possibly execute programs.

EPSS

Процентиль: 81%
0.01655
Низкий

Дефекты

CWE-79

Связанные уязвимости

ubuntu
около 19 лет назад

Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read CGI program source code, list directories, and possibly execute programs.

nvd
около 19 лет назад

Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read CGI program source code, list directories, and possibly execute programs.

debian
около 19 лет назад

Webmin before 1.296 and Usermin before 1.226 do not properly handle a ...

EPSS

Процентиль: 81%
0.01655
Низкий

Дефекты

CWE-79