CVE Vulnerabilities

CVE-2006-4246

Published: Sep 19, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.6 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Usermin before 1.220 (20060629) allows remote attackers to read arbitrary files, possibly related to chfn/save.cgi not properly handling an empty shell parameter, which results in changing roots shell instead of the shell of a specified user.

Affected Software

NameVendorStart VersionEnd Version
UserminUsermin*1.210 (including)
UserminUsermin0.4 (including)0.4 (including)
UserminUsermin0.5 (including)0.5 (including)
UserminUsermin0.6 (including)0.6 (including)
UserminUsermin0.7 (including)0.7 (including)
UserminUsermin0.8 (including)0.8 (including)
UserminUsermin0.9 (including)0.9 (including)
UserminUsermin0.91 (including)0.91 (including)
UserminUsermin0.92 (including)0.92 (including)
UserminUsermin0.93 (including)0.93 (including)
UserminUsermin0.94 (including)0.94 (including)
UserminUsermin0.95 (including)0.95 (including)
UserminUsermin0.96 (including)0.96 (including)
UserminUsermin0.97 (including)0.97 (including)
UserminUsermin0.98 (including)0.98 (including)
UserminUsermin0.99 (including)0.99 (including)
UserminUsermin1.000 (including)1.000 (including)
UserminUsermin1.010 (including)1.010 (including)
UserminUsermin1.020 (including)1.020 (including)
UserminUsermin1.030 (including)1.030 (including)
UserminUsermin1.040 (including)1.040 (including)
UserminUsermin1.051 (including)1.051 (including)
UserminUsermin1.060 (including)1.060 (including)
UserminUsermin1.070 (including)1.070 (including)
UserminUsermin1.080 (including)1.080 (including)
UserminUsermin1.090 (including)1.090 (including)
UserminUsermin1.100 (including)1.100 (including)
UserminUsermin1.110 (including)1.110 (including)
UserminUsermin1.120 (including)1.120 (including)
UserminUsermin1.130 (including)1.130 (including)
UserminUsermin1.140 (including)1.140 (including)
UserminUsermin1.150 (including)1.150 (including)

References