Skip to content
Noroxi

Webmin records

112 published records for vendor webmin.

All records

112 records
  • An issue was discovered in Webmin <=1.920.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    webmin · webminAug 15, 2019

  • CVE-2022-36446
    68This week

    software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.

    CriticalCVSS 9.8WeaponizedEPSS 96%

    webmin · webminJul 25, 2022

  • CVE-2022-0824
    64This week

    Improper Access Control to Remote Code Execution in webmin/webmin

    HighCVSS 8.8WeaponizedEPSS 97%

    webmin · webminMar 2, 2022

  • In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the dat

    HighCVSS 8.8WeaponizedEPSS 78%

    webmin · webminJun 15, 2019

  • Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process featur

    CriticalCVSS 9.6Proof of conceptEPSS 34%

    webmin · webminApr 25, 2021

  • An Improper Data Validation Vulnerability exists in Webmin 1.941 and earlier affecting the Command Shell Endpoint.

    MediumCVSS 5.4No exploitEPSS 80%

    webmin · webminOct 12, 2020

  • rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an e

    HighCVSS 8.8Proof of conceptEPSS 35%

    webmin · webminAug 26, 2019

  • Webmin CGI Command Injection Remote Code Execution Vulnerability

    HighCVSS 8.8Proof of conceptEPSS 33%

    webmin · webminDec 30, 2024

  • miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage

    CriticalCVSS 10.0Proof of conceptEPSS 15%

    usermin · userminMar 3, 2003

  • Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read ar

    MediumCVSS 5.0WeaponizedEPSS 78%

    usermin · userminJul 6, 2006

  • Arbitrary command execution can occur in Webmin through 1.962.

    HighCVSS 8.8Proof of conceptEPSS 28%

    webmin · webminDec 21, 2020

  • Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in th

    CriticalCVSS 10.0Proof of conceptEPSS 10%

    webmin · webminDec 17, 2001

  • The Printer Administration module for Webmin 0.990 and earlier allows remote attackers to execute arbitrary commands via shell metacharacter

    CriticalCVSS 10.0No exploitEPSS 3%

    webmin · webminDec 31, 2002

  • Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, w

    CriticalCVSS 10.0No exploitEPSS 2%

    usermin · userminMay 2, 2005

  • An issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is enabled.

    CriticalCVSS 9.8No exploitEPSS 2%

    webmin · webminMar 14, 2018

  • miniserv.pl in Webmin 1.962 on Windows mishandles special characters in query arguments to the CGI program.

    CriticalCVSS 9.8No exploitEPSS 2%

    webmin · webminDec 29, 2020

  • A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.

    CriticalCVSS 9.6Proof of conceptEPSS 4%

    webmin · webminApr 11, 2022

  • CVE-2019-9624
    38Monitor

    Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges to

    HighCVSS 7.8WeaponizedEPSS 24%

    webmin · webminMar 7, 2019

  • Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a

    HighCVSS 8.8Proof of conceptEPSS 9%

    webmin · webminApr 25, 2021

  • Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to achieve Remote Command Execution (RCE) through Webmin's running process fea

    HighCVSS 8.8Proof of conceptEPSS 8%

    webmin · webminApr 25, 2021

  • CVE-2002-2360
    38Monitor

    The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to ar

    CriticalCVSS 9.3Proof of conceptEPSS 4%

    webmin · webminDec 31, 2002

  • SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:80

    HighCVSS 8.6Proof of conceptEPSS 9%

    webmin · webminOct 19, 2017

  • CVE-2007-5066
    37Monitor

    Unspecified vulnerability in Webmin before 1.370 on Windows allows remote authenticated users to execute arbitrary commands via a crafted UR

    CriticalCVSS 9.0No exploitEPSS 2%

    webmin · webminSep 24, 2007

  • Webmin through 1.991, when the Authentic theme is used, allows remote code execution when a user has been manually created (i.e., not create

    HighCVSS 8.8No exploitEPSS 4%

    webmin · webminMay 14, 2022

  • CSRF exists in Webmin 1.850.

    HighCVSS 8.8Proof of conceptEPSS 3%

    webmin · webminOct 19, 2017