VYPR
Unrated severityNVD Advisory· Published Jun 11, 2007· Updated Apr 23, 2026

CVE-2007-3156

CVE-2007-3156

Description

Multiple cross-site scripting (XSS) vulnerabilities in pam_login.cgi in Webmin before 1.350 and Usermin before 1.280 allow remote attackers to inject arbitrary web script or HTML via the (1) cid, (2) message, or (3) question parameter. NOTE: some of these details are obtained from third party information.

Affected products

2
  • cpe:2.3:a:webmin:usermin:*:*:*:*:*:*:*:*
    Range: <=1.280
  • cpe:2.3:a:webmin:webmin:*:*:*:*:*:*:*:*
    Range: <=1.340

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

10

News mentions

0

No linked articles in our index yet.