Webmin before 1.290 and Usermin before 1.220 contain a path traversal caused by calling the simplify_path function before decoding HTML, letting remote attackers read arbitrary files, exploit requires sending crafted '..%01' sequences.
id: CVE-2006-3392
info:
name: Webmin < 1.290 / Usermin < 1.220 - Arbitrary File Disclosure
auth
...