Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Webmin < 1.290 / Usermin < 1.220 - Arbitrary File Disclosure (Python3) | https://github.com/0xtz/CVE-2006-3392 | POC Details |
| 2 | This small script helps to avoid using MetaSploit (msfconsole) during the Enterprise pentests and OSCP-like exams. Grep included function will help you to get only the important information. | https://github.com/IvanGlinkin/CVE-2006-3392 | POC Details |
| 3 | It is a simple tool to exploit local file include . vulnerabilities | https://github.com/Adel-kaka-dz/CVE-2006-3392 | POC Details |
| 4 | Python script to exploit webmin vulnerability cve-2006-3392 | https://github.com/gb21oc/ExploitWebmin | POC Details |
| 5 | Webmin Local File Include (unauthenticated) | https://github.com/kernel-cyber/CVE-2006-3392 | POC Details |
| 6 | Webmin < 1.290 / Usermin < 1.220 - Arbitrary file disclosure | https://github.com/g1vi/CVE-2006-3392 | POC Details |
| 7 | None | https://github.com/MrEmpy/CVE-2006-3392 | POC Details |
| 8 | None | https://github.com/brosck/CVE-2006-3392 | POC Details |
| 9 | Webmin before 1.290 and Usermin before 1.220 contain a path traversal caused by calling the simplify_path function before decoding HTML, letting remote attackers read arbitrary files, exploit requires sending crafted '..%01' sequences. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2006/CVE-2006-3392.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2006-3393 | NASCAR Racing UDP Datagram远程拒绝服务漏洞 | |
| CVE-2006-3360 | phpSysInfo 'Index.php'目录遍历漏洞 | |
| CVE-2006-3354 | Microsoft Internet Explorer ADODB.Recordset空指针引用拒绝服务漏洞 | |
| CVE-2006-3402 | VirtuaStore Password 参数SQL注入漏洞 | |
| CVE-2006-3352 | 作废: Mozilla Firefox OuterHTML重定向处理信息泄露漏洞 | |
| CVE-2006-3351 | Microsoft Windows explorer.exe URL文件格式溢出漏洞 | |
| CVE-2006-3404 | Gimp XCF_load_vector函数栈溢出漏洞 | |
| CVE-2006-3353 | Opera Document Stylesheet iframe和JavaScript拒绝服务漏洞 | |
| CVE-2006-3395 | SiteBuilder-FX 'Top.PHP'远程文件包含漏洞 | |
| CVE-2006-3394 | BXCP 'Index.PHP' SQL注入漏洞 | |
| CVE-2006-3396 | Galleria远程文件包含漏洞 | |
| CVE-2006-3391 | IMBCContents不安全ActiveX 'Execute()' 方法代码执行漏洞 | |
| CVE-2006-3390 | WordPress错误paged参数SQL操作信息泄露漏洞 | |
| CVE-2006-3389 | WordPress错误paged参数SQL操作信息泄露漏洞 | |
| CVE-2006-3388 | PHPMyAdmin Table参数跨站脚本攻击漏洞 | |
| CVE-2006-3387 | Fusion News 'post.ph'目录遍历漏洞 | |
| CVE-2006-3386 | Vincent Leclercq News 'index.php'安装路径等敏感信息泄露漏洞 | |
| CVE-2006-3385 | Vincent Leclercq News 'divers.php'跨站脚本攻击漏洞 | |
| CVE-2006-3384 | Vincent Leclercq News跨站脚本攻击漏洞 | |
| CVE-2006-3383 | mAds 1.0中的 'index.php' 跨站脚本攻击(XSS)漏洞。 |
Showing top 20 of 53 CVEs. View all on vendor page → →
No comments yet