Directory traversal vulnerability in Webmin before 1.280, when run on Windows, allows remote attackers to read arbitrary files via \ (backslash) characters in the URL to certain directories under the web root, such as the image directory.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/MrEmpy/CVE-2006-3392
- https://github.com/brosck/CVE-2006-3392
- https://github.com/g1vi/CVE-2006-3392