CVE-2006-3392
NUCLEIWebmin <1.290 - Info Disclosure
Title source: llmDescription
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes such as "%01" are removed from the filename. NOTE: This is a different issue than CVE-2006-3274.
Exploits (10)
exploitdb
WORKING POC
VERIFIED
by joffer · phpremotemultiple
https://www.exploit-db.com/exploits/1997
metasploit
WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/webmin/file_disclosure.rb
Nuclei Templates (1)
Webmin < 1.290 / Usermin < 1.220 - Arbitrary File Disclosure
MEDIUMby s4e-io
Shodan:
http.title:"webmin"
FOFA:
title="webmin"
References (18)
Scores
EPSS
0.7860
EPSS Percentile
99.0%
Details
Status
published
Products (2)
usermin/usermin
< 1.210
webmin/webmin
< 1.2.80
Published
Jul 06, 2006
Tracked Since
Feb 18, 2026