CVE-2008-0720
Webmin Usermin - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in Webmin 1.370 and 1.390 and Usermin 1.300 and 1.320 allows remote attackers to inject arbitrary web script or HTML via the search parameter to webmin_search.cgi (aka the search section), and possibly other components accessed through a "search box" or "open file box." NOTE: some of these details are obtained from third party information.
References (6)
Scores
EPSS
0.0047
EPSS Percentile
64.5%
Classification
CWE
CWE-79
Status
draft
Affected Products (4)
webmin/usermin
webmin/usermin
webmin/webmin
webmin/webmin
Timeline
Published
Feb 12, 2008
Tracked Since
Feb 18, 2026