Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read CGI program source code, list directories, and possibly execute programs.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Webmin和Usermin 跨站脚本攻击漏洞
Vulnerability Description
Webmin 1.296之前和Usermin 1.226之前的版本,未适当处理具有空("%00")字符的URL,远程攻击者可能执行跨站脚本攻击(XSS)、读取CGI程序源代码、列出目录并可能执行程序。
CVSS Information
N/A
Vulnerability Type
N/A