Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-2079


Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argument) form of Perl open.


Published

2025-04-28T15:15:44.007

Last Modified

2025-05-14T18:59:44.720

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.9 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-96
  • Type: Primary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application webmin usermin < 1.660 Yes

References