CVE-2006-3392

NUCLEI

Webmin <1.290 - Info Disclosure

Title source: llm

Description

Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes such as "%01" are removed from the filename. NOTE: This is a different issue than CVE-2006-3274.

Exploits (10)

exploitdb WORKING POC VERIFIED
by UmZ · perlremotemultiple
https://www.exploit-db.com/exploits/2017
exploitdb WORKING POC VERIFIED
by joffer · phpremotemultiple
https://www.exploit-db.com/exploits/1997
nomisec WORKING POC 14 stars
by IvanGlinkin · poc
https://github.com/IvanGlinkin/CVE-2006-3392
nomisec WORKING POC 3 stars
by brosck · poc
https://github.com/brosck/CVE-2006-3392
nomisec WORKING POC 1 stars
by g1vi · poc
https://github.com/g1vi/CVE-2006-3392
nomisec WORKING POC 1 stars
by 0xtz · poc
https://github.com/0xtz/CVE-2006-3392
nomisec WORKING POC
by gb21oc · poc
https://github.com/gb21oc/ExploitWebmin
nomisec WORKING POC
by kernel-cyber · poc
https://github.com/kernel-cyber/CVE-2006-3392
nomisec WORKING POC
by Adel-kaka-dz · poc
https://github.com/Adel-kaka-dz/CVE-2006-3392
metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/webmin/file_disclosure.rb

Nuclei Templates (1)

Webmin < 1.290 / Usermin < 1.220 - Arbitrary File Disclosure
MEDIUMby s4e-io
Shodan: http.title:"webmin"
FOFA: title="webmin"

Scores

EPSS 0.7860
EPSS Percentile 99.0%

Details

Status published
Products (2)
usermin/usermin < 1.210
webmin/webmin < 1.2.80
Published Jul 06, 2006
Tracked Since Feb 18, 2026