Mandriva Linux Security Advisory MDKSA-2006-170: Webmin before 1.296 and Usermin before 1.226 does not properly handle a URL with a null (“%00”) character, which allows remote attackers to conduct cross-site scripting (XSS), read CGI program source code, list directories, and possibly execute programs.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/50365/MDKSA-2006-170.txt
Source: https://packetstormsecurity.com/files/50365/Mandriva-Linux-Security-Advisory-2006.170.html

