Записи Webmin
112 опубликованных записей вендора webmin.
Профиль для исследователя
- Попали в KEV
- 1 · 0,9 %
- С эксплойтом
- 6 · 5,4 %
- Pre-auth RCE
- 11
- С записью об исправлении
- 8,9 %
- Медиана: публикация → KEV
- 953 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')56
- CWE-352 Cross-Site Request Forgery (CSRF)8
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')6
- CWE-284 Improper Access Control2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-269 Improper Privilege Management1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
112 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2019-15107Готовый эксплойт | An issue was discovered in Webmin <=1.920.webmin · webmin · CWE-78 | Критическая9,8 | KEV | 99,7 % | 15 авг. 2019 г. |
68На этой неделе | CVE-2022-36446Готовый эксплойт | software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.webmin · webmin · CWE-116 | Критическая9,8 | — | 96,0 % | 25 июл. 2022 г. |
64На этой неделе | CVE-2022-0824Готовый эксплойт | Improper Access Control to Remote Code Execution in webmin/webminwebmin · webmin · CWE-284 | Высокая8,8 | — | 97,0 % | 2 мар. 2022 г. |
58В плане | CVE-2019-12840Готовый эксплойт | In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the datwebmin · webmin · CWE-78 | Высокая8,8 | — | 77,8 % | 15 июн. 2019 г. |
48В плане | CVE-2021-31761Proof of concept | Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process featurwebmin · webmin · CWE-79 | Критическая9,6 | — | 33,6 % | 25 апр. 2021 г. |
45В плане | CVE-2020-8821Эксплойта нет | An Improper Data Validation Vulnerability exists in Webmin 1.941 and earlier affecting the Command Shell Endpoint.webmin · webmin · CWE-79 | Средняя5,4 | — | 80,2 % | 12 окт. 2020 г. |
45В плане | CVE-2019-15642Proof of concept | rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an ewebmin · webmin · CWE-94 | Высокая8,8 | — | 34,8 % | 26 авг. 2019 г. |
45В плане | CVE-2024-12828Proof of concept | Webmin CGI Command Injection Remote Code Execution Vulnerabilitywebmin · webmin · CWE-78 | Высокая8,8 | — | 33,5 % | 30 дек. 2024 г. |
45В плане | CVE-2003-0101Proof of concept | miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage usermin · usermin | Критическая10,0 | — | 15,5 % | 3 мар. 2003 г. |
43В плане | CVE-2006-3392Готовый эксплойт | Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arusermin · usermin | Средняя5,0 | — | 78,3 % | 6 июл. 2006 г. |
43В плане | CVE-2020-35606Proof of concept | Arbitrary command execution can occur in Webmin through 1.962.webmin · webmin · CWE-78 | Высокая8,8 | — | 28,0 % | 21 дек. 2020 г. |
43В плане | CVE-2001-1196Proof of concept | Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in thwebmin · webmin | Критическая10,0 | — | 9,8 % | 17 дек. 2001 г. |
41В плане | CVE-2002-2201Эксплойта нет | The Printer Administration module for Webmin 0.990 and earlier allows remote attackers to execute arbitrary commands via shell metacharacterwebmin · webmin | Критическая10,0 | — | 3,3 % | 31 дек. 2002 г. |
41В плане | CVE-2005-1177Эксплойта нет | Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, wusermin · usermin | Критическая10,0 | — | 1,8 % | 2 мая 2005 г. |
40В плане | CVE-2018-8712Эксплойта нет | An issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is enabled.webmin · webmin · CWE-22 | Критическая9,8 | — | 1,8 % | 14 мар. 2018 г. |
40В плане | CVE-2020-35769Эксплойта нет | miniserv.pl in Webmin 1.962 on Windows mishandles special characters in query arguments to the CGI program.webmin · webmin | Критическая9,8 | — | 1,8 % | 29 дек. 2020 г. |
39Наблюдать | CVE-2021-32157Proof of concept | A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.webmin · webmin · CWE-79 | Критическая9,6 | — | 4,0 % | 11 апр. 2022 г. |
38Наблюдать | CVE-2019-9624Готовый эксплойт | Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges towebmin · webmin · CWE-269 | Высокая7,8 | — | 23,7 % | 7 мар. 2019 г. |
38Наблюдать | CVE-2021-31762Proof of concept | Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get awebmin · webmin · CWE-352 | Высокая8,8 | — | 8,8 % | 25 апр. 2021 г. |
38Наблюдать | CVE-2021-31760Proof of concept | Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to achieve Remote Command Execution (RCE) through Webmin's running process feawebmin · webmin · CWE-352 | Высокая8,8 | — | 8,5 % | 25 апр. 2021 г. |
38Наблюдать | CVE-2002-2360Proof of concept | The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to arwebmin · webmin · CWE-264 | Критическая9,3 | — | 3,6 % | 31 дек. 2002 г. |
37Наблюдать | CVE-2017-15644Proof of concept | SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:80webmin · webmin · CWE-918 | Высокая8,6 | — | 8,9 % | 19 окт. 2017 г. |
37Наблюдать | CVE-2007-5066Эксплойта нет | Unspecified vulnerability in Webmin before 1.370 on Windows allows remote authenticated users to execute arbitrary commands via a crafted URwebmin · webmin · CWE-20 | Критическая9,0 | — | 2,4 % | 24 сент. 2007 г. |
36Наблюдать | CVE-2022-30708Эксплойта нет | Webmin through 1.991, when the Authentic theme is used, allows remote code execution when a user has been manually created (i.e., not createwebmin · webmin | Высокая8,8 | — | 3,6 % | 14 мая 2022 г. |
36Наблюдать | CVE-2017-15645Proof of concept | CSRF exists in Webmin 1.850.webmin · webmin · CWE-352 | Высокая8,8 | — | 3,2 % | 19 окт. 2017 г. |
- CVE-2019-1510799Срочно
An issue was discovered in Webmin <=1.920.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %webmin · webmin15 авг. 2019 г.
- CVE-2022-3644668На этой неделе
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
КритическаяCVSS 9,8Готовый эксплойтEPSS 96 %webmin · webmin25 июл. 2022 г.
- CVE-2022-082464На этой неделе
Improper Access Control to Remote Code Execution in webmin/webmin
ВысокаяCVSS 8,8Готовый эксплойтEPSS 97 %webmin · webmin2 мар. 2022 г.
- CVE-2019-1284058В плане
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the dat
ВысокаяCVSS 8,8Готовый эксплойтEPSS 78 %webmin · webmin15 июн. 2019 г.
- CVE-2021-3176148В плане
Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process featur
КритическаяCVSS 9,6Proof of conceptEPSS 34 %webmin · webmin25 апр. 2021 г.
- CVE-2020-882145В плане
An Improper Data Validation Vulnerability exists in Webmin 1.941 and earlier affecting the Command Shell Endpoint.
СредняяCVSS 5,4Эксплойта нетEPSS 80 %webmin · webmin12 окт. 2020 г.
- CVE-2019-1564245В плане
rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an e
ВысокаяCVSS 8,8Proof of conceptEPSS 35 %webmin · webmin26 авг. 2019 г.
- CVE-2024-1282845В плане
Webmin CGI Command Injection Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Proof of conceptEPSS 33 %webmin · webmin30 дек. 2024 г.
- CVE-2003-010145В плане
miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage
КритическаяCVSS 10,0Proof of conceptEPSS 15 %usermin · usermin3 мар. 2003 г.
- CVE-2006-339243В плане
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read ar
СредняяCVSS 5,0Готовый эксплойтEPSS 78 %usermin · usermin6 июл. 2006 г.
- CVE-2020-3560643В плане
Arbitrary command execution can occur in Webmin through 1.962.
ВысокаяCVSS 8,8Proof of conceptEPSS 28 %webmin · webmin21 дек. 2020 г.
- CVE-2001-119643В плане
Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in th
КритическаяCVSS 10,0Proof of conceptEPSS 10 %webmin · webmin17 дек. 2001 г.
- CVE-2002-220141В плане
The Printer Administration module for Webmin 0.990 and earlier allows remote attackers to execute arbitrary commands via shell metacharacter
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %webmin · webmin31 дек. 2002 г.
- CVE-2005-117741В плане
Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, w
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %usermin · usermin2 мая 2005 г.
- CVE-2018-871240В плане
An issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is enabled.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %webmin · webmin14 мар. 2018 г.
- CVE-2020-3576940В плане
miniserv.pl in Webmin 1.962 on Windows mishandles special characters in query arguments to the CGI program.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %webmin · webmin29 дек. 2020 г.
- CVE-2021-3215739Наблюдать
A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.
КритическаяCVSS 9,6Proof of conceptEPSS 4 %webmin · webmin11 апр. 2022 г.
- CVE-2019-962438Наблюдать
Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges to
ВысокаяCVSS 7,8Готовый эксплойтEPSS 24 %webmin · webmin7 мар. 2019 г.
- CVE-2021-3176238Наблюдать
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a
ВысокаяCVSS 8,8Proof of conceptEPSS 9 %webmin · webmin25 апр. 2021 г.
- CVE-2021-3176038Наблюдать
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to achieve Remote Command Execution (RCE) through Webmin's running process fea
ВысокаяCVSS 8,8Proof of conceptEPSS 8 %webmin · webmin25 апр. 2021 г.
- CVE-2002-236038Наблюдать
The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to ar
КритическаяCVSS 9,3Proof of conceptEPSS 4 %webmin · webmin31 дек. 2002 г.
- CVE-2017-1564437Наблюдать
SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:80
ВысокаяCVSS 8,6Proof of conceptEPSS 9 %webmin · webmin19 окт. 2017 г.
- CVE-2007-506637Наблюдать
Unspecified vulnerability in Webmin before 1.370 on Windows allows remote authenticated users to execute arbitrary commands via a crafted UR
КритическаяCVSS 9,0Эксплойта нетEPSS 2 %webmin · webmin24 сент. 2007 г.
- CVE-2022-3070836Наблюдать
Webmin through 1.991, when the Authentic theme is used, allows remote code execution when a user has been manually created (i.e., not create
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %webmin · webmin14 мая 2022 г.
- CVE-2017-1564536Наблюдать
CSRF exists in Webmin 1.850.
ВысокаяCVSS 8,8Proof of conceptEPSS 3 %webmin · webmin19 окт. 2017 г.