Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using ..%01 sequences, which bypass the removal of ../ sequences before bytes such as %01 are removed from the filename. NOTE: This is a different issue than CVE-2006-3274.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Usermin | Usermin | * | 1.210 (including) |
| Webmin | Webmin | * | 1.2.80 (including) |