Show plain JSON{"cve": {"data_type": "CVE", "references": {"reference_data": [{"url": "http://attrition.org/pipermail/vim/2006-June/000912.html", "name": "20060630 Webmin traversal - changelog", "tags": [], "refsource": "VIM"}, {"url": "http://www.webmin.com/changes.html", "name": "http://www.webmin.com/changes.html", "tags": [], "refsource": "CONFIRM"}, {"url": "http://www.osvdb.org/26772", "name": "26772", "tags": ["Patch"], "refsource": "OSVDB"}, {"url": "http://secunia.com/advisories/20892", "name": "20892", "tags": ["Patch", "Vendor Advisory"], "refsource": "SECUNIA"}, {"url": "http://www.kb.cert.org/vuls/id/999601", "name": "VU#999601", "tags": ["US Government Resource"], "refsource": "CERT-VN"}, {"url": "http://attrition.org/pipermail/vim/2006-July/000923.html", "name": "20060711 Re: Webmin traversal - changelog", "tags": [], "refsource": "VIM"}, {"url": "http://www.securityfocus.com/bid/18744", "name": "18744", "tags": [], "refsource": "BID"}, {"url": "http://secunia.com/advisories/21105", "name": "21105", "tags": ["Vendor Advisory"], "refsource": "SECUNIA"}, {"url": "http://security.gentoo.org/glsa/glsa-200608-11.xml", "name": "GLSA-200608-11", "tags": [], "refsource": "GENTOO"}, {"url": "http://secunia.com/advisories/21365", "name": "21365", "tags": ["Patch", "Vendor Advisory"], "refsource": "SECUNIA"}, {"url": "http://www.debian.org/security/2006/dsa-1199", "name": "DSA-1199", "tags": [], "refsource": "DEBIAN"}, {"url": "http://secunia.com/advisories/22556", "name": "22556", "tags": ["Vendor Advisory"], "refsource": "SECUNIA"}, {"url": "http://www.securityfocus.com/archive/1/440466/100/0/threaded", "name": "20060715 Re: Webmin / Usermin Arbitrary File Disclosure Vulnerability exploit", "tags": [], "refsource": "BUGTRAQ"}, {"url": "http://www.mandriva.com/security/advisories?name=MDKSA-2006:125", "name": "MDKSA-2006:125", "tags": [], "refsource": "MANDRIVA"}, {"url": "http://www.vupen.com/english/advisories/2006/2612", "name": "ADV-2006-2612", "tags": ["Vendor Advisory"], "refsource": "VUPEN"}, {"url": "http://www.securityfocus.com/archive/1/440493/100/0/threaded", "name": "20060715 Webmin / Usermin Arbitrary File Disclosure Vulnerability Perl", "tags": [], "refsource": "BUGTRAQ"}, {"url": "http://www.securityfocus.com/archive/1/440125/100/0/threaded", "name": "20060710 Re: Webmin / Usermin Arbitrary File Disclosure Vulnerability exploit", "tags": [], "refsource": "BUGTRAQ"}, {"url": "http://www.securityfocus.com/archive/1/439653/100/0/threaded", "name": "20060709 Webmin / Usermin Arbitrary File Disclosure Vulnerability exploit", "tags": [], "refsource": "BUGTRAQ"}]}, "data_format": "MITRE", "description": {"description_data": [{"lang": "en", "value": "Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using \"..%01\" sequences, which bypass the removal of \"../\" sequences before bytes such as \"%01\" are removed from the filename. NOTE: This is a different issue than CVE-2006-3274."}]}, "problemtype": {"problemtype_data": [{"description": [{"lang": "en", "value": "NVD-CWE-Other"}]}]}, "data_version": "4.0", "CVE_data_meta": {"ID": "CVE-2006-3392", "ASSIGNER": "cve@mitre.org"}}, "impact": {"baseMetricV2": {"cvssV2": {"version": "2.0", "baseScore": 5.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "severity": "MEDIUM", "impactScore": 2.9, "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}}, "publishedDate": "2006-07-06T20:05Z", "configurations": {"nodes": [{"children": [], "operator": "OR", "cpe_match": [{"cpe23Uri": "cpe:2.3:a:webmin:webmin:*:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true, "versionEndIncluding": "1.2.80"}, {"cpe23Uri": "cpe:2.3:a:usermin:usermin:*:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true, "versionEndIncluding": "1.210"}]}], "CVE_data_version": "4.0"}, "lastModifiedDate": "2018-10-18T16:47Z"}