Vulnerabilities
Vulnerable Software
Webmin:  >> Webmin  >> 1.900  Security Vulnerabilities
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data parameter to update.cgi.
CVSS Score
8.8
EPSS Score
0.713
Published
2019-06-15
Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges to upload a crafted .cgi file via the /updown/upload.cgi URI.
CVSS Score
7.8
EPSS Score
0.35
Published
2019-03-07


Contact Us

Shodan ® - All rights reserved