Multiple cross-site scripting (XSS) vulnerabilities in chooser.cgi in Webmin before 1.330 and Usermin before 1.260 allow remote attackers to inject arbitrary web script or HTML via a crafted filename.
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Usermin | Usermin | 1.000 (including) | 1.000 (including) |
Usermin | Usermin | 1.010 (including) | 1.010 (including) |
Usermin | Usermin | 1.020 (including) | 1.020 (including) |
Usermin | Usermin | 1.030 (including) | 1.030 (including) |
Usermin | Usermin | 1.040 (including) | 1.040 (including) |
Usermin | Usermin | 1.051 (including) | 1.051 (including) |
Usermin | Usermin | 1.060 (including) | 1.060 (including) |
Usermin | Usermin | 1.070 (including) | 1.070 (including) |
Usermin | Usermin | 1.080 (including) | 1.080 (including) |
Usermin | Usermin | 1.090 (including) | 1.090 (including) |
Usermin | Usermin | 1.100 (including) | 1.100 (including) |
Usermin | Usermin | 1.110 (including) | 1.110 (including) |
Usermin | Usermin | 1.120 (including) | 1.120 (including) |
Usermin | Usermin | 1.130 (including) | 1.130 (including) |
Usermin | Usermin | 1.140 (including) | 1.140 (including) |
Usermin | Usermin | 1.150 (including) | 1.150 (including) |
Usermin | Usermin | 1.210 (including) | 1.210 (including) |
Usermin | Usermin | 1.220 (including) | 1.220 (including) |
Usermin | Usermin | 1.230 (including) | 1.230 (including) |
Usermin | Usermin | 1.240 (including) | 1.240 (including) |
Usermin | Usermin | 1.250 (including) | 1.250 (including) |
Webmin | Webmin | 1.0.00 (including) | 1.0.00 (including) |
Webmin | Webmin | 1.0.10 (including) | 1.0.10 (including) |
Webmin | Webmin | 1.0.20 (including) | 1.0.20 (including) |
Webmin | Webmin | 1.0.30 (including) | 1.0.30 (including) |
Webmin | Webmin | 1.0.40 (including) | 1.0.40 (including) |
Webmin | Webmin | 1.0.50 (including) | 1.0.50 (including) |
Webmin | Webmin | 1.0.51 (including) | 1.0.51 (including) |
Webmin | Webmin | 1.0.60 (including) | 1.0.60 (including) |
Webmin | Webmin | 1.0.70 (including) | 1.0.70 (including) |
Webmin | Webmin | 1.0.80 (including) | 1.0.80 (including) |
Webmin | Webmin | 1.0.90 (including) | 1.0.90 (including) |
Webmin | Webmin | 1.1.00 (including) | 1.1.00 (including) |
Webmin | Webmin | 1.1.10 (including) | 1.1.10 (including) |
Webmin | Webmin | 1.1.20 (including) | 1.1.20 (including) |
Webmin | Webmin | 1.1.21 (including) | 1.1.21 (including) |
Webmin | Webmin | 1.1.30 (including) | 1.1.30 (including) |
Webmin | Webmin | 1.1.40 (including) | 1.1.40 (including) |
Webmin | Webmin | 1.1.50 (including) | 1.1.50 (including) |
Webmin | Webmin | 1.2.20 (including) | 1.2.20 (including) |
Webmin | Webmin | 1.2.30 (including) | 1.2.30 (including) |
Webmin | Webmin | 1.2.40 (including) | 1.2.40 (including) |
Webmin | Webmin | 1.2.50 (including) | 1.2.50 (including) |
Webmin | Webmin | 1.3.20 (including) | 1.3.20 (including) |