Перейти к содержимому
Noroxi

Записи Webmin

112 опубликованных записей вендора webmin.

Профиль для исследователя

Попали в KEV
1 · 0,9 %
С эксплойтом
6 · 5,4 %
Pre-auth RCE
11
С записью об исправлении
8,9 %
Медиана: публикация → KEV
953 дн.

Все записи

112 записей
  • CVE-2019-15107
    99Срочно

    An issue was discovered in Webmin <=1.920.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    webmin · webmin15 авг. 2019 г.

  • CVE-2022-36446
    68На этой неделе

    software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.

    КритическаяCVSS 9,8Готовый эксплойтEPSS 96 %

    webmin · webmin25 июл. 2022 г.

  • CVE-2022-0824
    64На этой неделе

    Improper Access Control to Remote Code Execution in webmin/webmin

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 97 %

    webmin · webmin2 мар. 2022 г.

  • CVE-2019-12840
    58В плане

    In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the dat

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 78 %

    webmin · webmin15 июн. 2019 г.

  • CVE-2021-31761
    48В плане

    Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process featur

    КритическаяCVSS 9,6Proof of conceptEPSS 34 %

    webmin · webmin25 апр. 2021 г.

  • CVE-2020-8821
    45В плане

    An Improper Data Validation Vulnerability exists in Webmin 1.941 and earlier affecting the Command Shell Endpoint.

    СредняяCVSS 5,4Эксплойта нетEPSS 80 %

    webmin · webmin12 окт. 2020 г.

  • CVE-2019-15642
    45В плане

    rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an e

    ВысокаяCVSS 8,8Proof of conceptEPSS 35 %

    webmin · webmin26 авг. 2019 г.

  • CVE-2024-12828
    45В плане

    Webmin CGI Command Injection Remote Code Execution Vulnerability

    ВысокаяCVSS 8,8Proof of conceptEPSS 33 %

    webmin · webmin30 дек. 2024 г.

  • CVE-2003-0101
    45В плане

    miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage

    КритическаяCVSS 10,0Proof of conceptEPSS 15 %

    usermin · usermin3 мар. 2003 г.

  • CVE-2006-3392
    43В плане

    Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read ar

    СредняяCVSS 5,0Готовый эксплойтEPSS 78 %

    usermin · usermin6 июл. 2006 г.

  • CVE-2020-35606
    43В плане

    Arbitrary command execution can occur in Webmin through 1.962.

    ВысокаяCVSS 8,8Proof of conceptEPSS 28 %

    webmin · webmin21 дек. 2020 г.

  • CVE-2001-1196
    43В плане

    Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in th

    КритическаяCVSS 10,0Proof of conceptEPSS 10 %

    webmin · webmin17 дек. 2001 г.

  • CVE-2002-2201
    41В плане

    The Printer Administration module for Webmin 0.990 and earlier allows remote attackers to execute arbitrary commands via shell metacharacter

    КритическаяCVSS 10,0Эксплойта нетEPSS 3 %

    webmin · webmin31 дек. 2002 г.

  • CVE-2005-1177
    41В плане

    Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, w

    КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

    usermin · usermin2 мая 2005 г.

  • CVE-2018-8712
    40В плане

    An issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is enabled.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    webmin · webmin14 мар. 2018 г.

  • CVE-2020-35769
    40В плане

    miniserv.pl in Webmin 1.962 on Windows mishandles special characters in query arguments to the CGI program.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    webmin · webmin29 дек. 2020 г.

  • CVE-2021-32157
    39Наблюдать

    A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.

    КритическаяCVSS 9,6Proof of conceptEPSS 4 %

    webmin · webmin11 апр. 2022 г.

  • CVE-2019-9624
    38Наблюдать

    Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges to

    ВысокаяCVSS 7,8Готовый эксплойтEPSS 24 %

    webmin · webmin7 мар. 2019 г.

  • CVE-2021-31762
    38Наблюдать

    Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a

    ВысокаяCVSS 8,8Proof of conceptEPSS 9 %

    webmin · webmin25 апр. 2021 г.

  • CVE-2021-31760
    38Наблюдать

    Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to achieve Remote Command Execution (RCE) through Webmin's running process fea

    ВысокаяCVSS 8,8Proof of conceptEPSS 8 %

    webmin · webmin25 апр. 2021 г.

  • CVE-2002-2360
    38Наблюдать

    The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to ar

    КритическаяCVSS 9,3Proof of conceptEPSS 4 %

    webmin · webmin31 дек. 2002 г.

  • CVE-2017-15644
    37Наблюдать

    SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:80

    ВысокаяCVSS 8,6Proof of conceptEPSS 9 %

    webmin · webmin19 окт. 2017 г.

  • CVE-2007-5066
    37Наблюдать

    Unspecified vulnerability in Webmin before 1.370 on Windows allows remote authenticated users to execute arbitrary commands via a crafted UR

    КритическаяCVSS 9,0Эксплойта нетEPSS 2 %

    webmin · webmin24 сент. 2007 г.

  • CVE-2022-30708
    36Наблюдать

    Webmin through 1.991, when the Authentic theme is used, allows remote code execution when a user has been manually created (i.e., not create

    ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %

    webmin · webmin14 мая 2022 г.

  • CVE-2017-15645
    36Наблюдать

    CSRF exists in Webmin 1.850.

    ВысокаяCVSS 8,8Proof of conceptEPSS 3 %

    webmin · webmin19 окт. 2017 г.