Unrated severityNVD Advisory· Published Jun 11, 2007· Updated Apr 23, 2026
CVE-2007-3156
CVE-2007-3156
Description
Multiple cross-site scripting (XSS) vulnerabilities in pam_login.cgi in Webmin before 1.350 and Usermin before 1.280 allow remote attackers to inject arbitrary web script or HTML via the (1) cid, (2) message, or (3) question parameter. NOTE: some of these details are obtained from third party information.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- secunia.com/advisories/25580nvdPatchVendor Advisory
- www.securityfocus.com/bid/24381nvdPatch
- secunia.com/advisories/25785nvdVendor Advisory
- secunia.com/advisories/25956nvdVendor Advisory
- www.vupen.com/english/advisories/2007/2117nvdVendor Advisory
- osvdb.org/36932nvd
- security.gentoo.org/glsa/glsa-200707-05.xmlnvd
- www.mandriva.com/security/advisoriesnvd
- www.webmin.com/changes-1.350.htmlnvd
- www.webmin.com/security.htmlnvd
News mentions
0No linked articles in our index yet.