Unrated severityNVD Advisory· Published Jun 28, 2006· Updated Apr 16, 2026
CVE-2006-3274
CVE-2006-3274
Description
Directory traversal vulnerability in Webmin before 1.280, when run on Windows, allows remote attackers to read arbitrary files via \ (backslash) characters in the URL to certain directories under the web root, such as the image directory.
Affected products
5cpe:2.3:a:webmin:webmin:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:webmin:webmin:*:*:*:*:*:*:*:*range: <=1.2.70
- cpe:2.3:a:webmin:webmin:1.2.30:*:*:*:*:*:*:*
- cpe:2.3:a:webmin:webmin:1.2.40:*:*:*:*:*:*:*
- cpe:2.3:a:webmin:webmin:1.2.50:*:*:*:*:*:*:*
- cpe:2.3:a:webmin:webmin:1.2.60:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- secunia.com/advisories/20777nvdVendor Advisory
- jvn.jp/jp/JVN%2367974490/index.htmlnvd
- securityreason.com/securityalert/1161nvd
- securitytracker.com/idnvd
- www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/88_e.htmlnvd
- www.securityfocus.com/archive/1/438149/100/0/threadednvd
- www.securityfocus.com/bid/18613nvd
- www.vupen.com/english/advisories/2006/2493nvd
- www.webmin.com/changes.htmlnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/27366nvd
News mentions
0No linked articles in our index yet.