← Vulnerability feed

Vulnerability record · CVE-2006-3392 · published 6 July 2006

CVE-2006-3392: Webmin and Usermin path traversal allows arbitrary file read

Usermin · Usermin

Webmin before 1.290 and Usermin before 1.220 call simplify_path before decoding HTML, so crafted sequences such as "..%01" survive the removal of "../" and permit directory traversal. A remote attacker can therefore read files outside the intended web root, exposing configuration and credential material on the host.

5.0 CVSS 2.0 Medium EPSS 78% · top 0.4%
5.0CVSS 2.0 base score
78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
36References
16 Jun 2026Last modified by NVD

Description

Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes such as "%01" are removed from the filename. NOTE: This is a different issue than CVE-2006-3274.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityUnauthenticated remote file read with a very high EPSS score and known public discussion, though no KEV listing or confirmed in-the-wild exploitation is recorded.

What it is

Webmin before 1.290 and Usermin before 1.220 call simplify_path before decoding HTML, so crafted sequences such as "..%01" survive the removal of "../" and permit directory traversal. A remote attacker can therefore read files outside the intended web root, exposing configuration and credential material on the host.

Impact

An unauthenticated remote attacker gains read access to arbitrary files on the server, which can leak Webmin/Usermin configuration, password hashes and other sensitive data. There is no integrity or availability impact per the CVSS vector.

Attack surface

Reachable over the network via the Webmin/Usermin HTTP interface; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no ransomware association is documented, but EPSS is very high (0.783, 99.6th percentile), and public advisories and mailing-list discussions exist, so exploitation is plausible and likely widespread.

What to do

  • Upgrade Webmin to 1.290 or later and Usermin to 1.220 or later, or apply the vendor/distribution patches referenced in the advisories.
  • Restrict network access to Webmin/Usermin management ports to trusted administrative networks only.
  • Run Webmin/Usermin with least privilege and avoid storing plaintext credentials in files readable by the service.
  • Monitor vendor and distribution advisories (Gentoo, Debian, Mandriva) for updated packages and apply them promptly.

Detection

  • Inspect HTTP request logs for traversal patterns containing "..%01", "..%00" or similar encoded dot-dot sequences against Webmin/Usermin endpoints.
  • Alert on requests for files outside the expected web root, especially configuration and password files.
  • Correlate Webmin/Usermin access logs with unexpected reads of sensitive paths on the host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://attrition.org/pipermail/vim/2006-July/000923.html
http://attrition.org/pipermail/vim/2006-June/000912.html
http://secunia.com/advisories/20892 PatchVendor Advisory
http://secunia.com/advisories/21105 Vendor Advisory
http://secunia.com/advisories/21365 PatchVendor Advisory
http://secunia.com/advisories/22556 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200608-11.xml
http://www.debian.org/security/2006/dsa-1199
http://www.kb.cert.org/vuls/id/999601 US Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2006:125
http://www.osvdb.org/26772 Patch
http://www.securityfocus.com/archive/1/439653/100/0/threaded
http://www.securityfocus.com/archive/1/440125/100/0/threaded
http://www.securityfocus.com/archive/1/440466/100/0/threaded
http://www.securityfocus.com/archive/1/440493/100/0/threaded
http://www.securityfocus.com/bid/18744
http://www.vupen.com/english/advisories/2006/2612 Vendor Advisory
http://www.webmin.com/changes.html
http://attrition.org/pipermail/vim/2006-July/000923.html
http://attrition.org/pipermail/vim/2006-June/000912.html
http://secunia.com/advisories/20892 PatchVendor Advisory
http://secunia.com/advisories/21105 Vendor Advisory
http://secunia.com/advisories/21365 PatchVendor Advisory
http://secunia.com/advisories/22556 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200608-11.xml
http://www.debian.org/security/2006/dsa-1199
http://www.kb.cert.org/vuls/id/999601 US Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2006:125
http://www.osvdb.org/26772 Patch
http://www.securityfocus.com/archive/1/439653/100/0/threaded
http://www.securityfocus.com/archive/1/440125/100/0/threaded
http://www.securityfocus.com/archive/1/440466/100/0/threaded
http://www.securityfocus.com/archive/1/440493/100/0/threaded
http://www.securityfocus.com/bid/18744
http://www.vupen.com/english/advisories/2006/2612 Vendor Advisory
http://www.webmin.com/changes.html

Track CVE-2006-3392 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-15107Webmin password_change.cgi command injectionWebmin through 1.920 passes the 'old' parameter in password_change.cgi into a shell command without sanitization, allowing OS command injection. The …KEVEPSS 100%analysed10.0CVE-2005-1177Usermin vulnerabilityUnknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, with unkno…EPSS 1.8%10.0CVE-2003-0101Engardelinux guardian digital webtool vulnerabilityminiserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (…EPSS 15%10.0CVE-2002-2201Webmin vulnerabilityThe Printer Administration module for Webmin 0.990 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the …EPSS 3.3%10.0CVE-2001-1196Webmin vulnerabilityDirectory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in the argumen…EPSS 9.8%9.8CVE-2022-36446Webmin apt-lib.pl command injection via unescaped UI commandWebmin before 1.997 fails to HTML-escape a UI command in software/apt-lib.pl, allowing injection of commands through that interface. The flaw is remo…EPSS 96%analysed9.8CVE-2020-35769Webmin vulnerabilityminiserv.pl in Webmin 1.962 on Windows mishandles special characters in query arguments to the CGI program.EPSS 1.8%9.8CVE-2018-8712Webmin path traversal vulnerabilityAn issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is enabled. As a result of weak d…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2006-3392), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.