Description
Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in the argument.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by A. Ramos · textremotecgi
https://www.exploit-db.com/exploits/21183
References (4)
Core 4
Core References
Vendor Advisory vdb-entry
x_refsource_xf
http://www.iss.net/security_center/static/7711.php
Vendor Advisory mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/245980
Exploit, Patch, Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/3698
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=webmin-l&m=100865390306103&w=2
Scores
EPSS
0.0379
EPSS Percentile
88.1%
Details
Status
published
Products (1)
webmin/webmin
0.91
Published
Dec 17, 2001
Tracked Since
Feb 18, 2026