CVE-2006-4246

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/09/2006
Last modified:
20/07/2017

Description

Usermin before 1.220 (20060629) allows remote attackers to read arbitrary files, possibly related to chfn/save.cgi not properly handling an empty shell parameter, which results in changing root's shell instead of the shell of a specified user.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:usermin:usermin:*:*:*:*:*:*:*:* 1.210 (including)
cpe:2.3:a:usermin:usermin:0.4:*:*:*:*:*:*:*
cpe:2.3:a:usermin:usermin:0.5:*:*:*:*:*:*:*
cpe:2.3:a:usermin:usermin:0.6:*:*:*:*:*:*:*
cpe:2.3:a:usermin:usermin:0.7:*:*:*:*:*:*:*
cpe:2.3:a:usermin:usermin:0.8:*:*:*:*:*:*:*
cpe:2.3:a:usermin:usermin:0.9:*:*:*:*:*:*:*
cpe:2.3:a:usermin:usermin:0.91:*:*:*:*:*:*:*
cpe:2.3:a:usermin:usermin:0.92:*:*:*:*:*:*:*
cpe:2.3:a:usermin:usermin:0.93:*:*:*:*:*:*:*
cpe:2.3:a:usermin:usermin:0.94:*:*:*:*:*:*:*
cpe:2.3:a:usermin:usermin:0.95:*:*:*:*:*:*:*
cpe:2.3:a:usermin:usermin:0.96:*:*:*:*:*:*:*
cpe:2.3:a:usermin:usermin:0.97:*:*:*:*:*:*:*
cpe:2.3:a:usermin:usermin:0.98:*:*:*:*:*:*:*