İçeriğe atla
Noroxi

Webmin kayıtları

webmin üreticisine ait 112 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
1 · %0,9
Silahlaştırılmış
6 · %5,4
Pre-auth RCE
11
Düzeltme kaydı olan
%8,9
Yayından KEV’e ortanca
953 gün

Tüm kayıtlar

112 kayıt
  • An issue was discovered in Webmin <=1.920.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    webmin · webmin15 Ağu 2019

  • CVE-2022-36446
    68Bu hafta

    software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.

    KritikCVSS 9,8SilahlaştırılmışEPSS %96

    webmin · webmin25 Tem 2022

  • CVE-2022-0824
    64Bu hafta

    Improper Access Control to Remote Code Execution in webmin/webmin

    YüksekCVSS 8,8SilahlaştırılmışEPSS %97

    webmin · webmin2 Mar 2022

  • CVE-2019-12840
    58Planlayın

    In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the dat

    YüksekCVSS 8,8SilahlaştırılmışEPSS %78

    webmin · webmin15 Haz 2019

  • CVE-2021-31761
    48Planlayın

    Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process featur

    KritikCVSS 9,6Kavram kanıtıEPSS %34

    webmin · webmin25 Nis 2021

  • CVE-2020-8821
    45Planlayın

    An Improper Data Validation Vulnerability exists in Webmin 1.941 and earlier affecting the Command Shell Endpoint.

    OrtaCVSS 5,4İstismar yokEPSS %80

    webmin · webmin12 Eki 2020

  • CVE-2019-15642
    45Planlayın

    rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an e

    YüksekCVSS 8,8Kavram kanıtıEPSS %35

    webmin · webmin26 Ağu 2019

  • CVE-2024-12828
    45Planlayın

    Webmin CGI Command Injection Remote Code Execution Vulnerability

    YüksekCVSS 8,8Kavram kanıtıEPSS %33

    webmin · webmin30 Ara 2024

  • CVE-2003-0101
    45Planlayın

    miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage

    KritikCVSS 10,0Kavram kanıtıEPSS %15

    usermin · usermin3 Mar 2003

  • CVE-2006-3392
    43Planlayın

    Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read ar

    OrtaCVSS 5,0SilahlaştırılmışEPSS %78

    usermin · usermin6 Tem 2006

  • CVE-2020-35606
    43Planlayın

    Arbitrary command execution can occur in Webmin through 1.962.

    YüksekCVSS 8,8Kavram kanıtıEPSS %28

    webmin · webmin21 Ara 2020

  • CVE-2001-1196
    43Planlayın

    Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in th

    KritikCVSS 10,0Kavram kanıtıEPSS %10

    webmin · webmin17 Ara 2001

  • CVE-2002-2201
    41Planlayın

    The Printer Administration module for Webmin 0.990 and earlier allows remote attackers to execute arbitrary commands via shell metacharacter

    KritikCVSS 10,0İstismar yokEPSS %3

    webmin · webmin31 Ara 2002

  • CVE-2005-1177
    41Planlayın

    Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, w

    KritikCVSS 10,0İstismar yokEPSS %2

    usermin · usermin2 May 2005

  • CVE-2018-8712
    40Planlayın

    An issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is enabled.

    KritikCVSS 9,8İstismar yokEPSS %2

    webmin · webmin14 Mar 2018

  • CVE-2020-35769
    40Planlayın

    miniserv.pl in Webmin 1.962 on Windows mishandles special characters in query arguments to the CGI program.

    KritikCVSS 9,8İstismar yokEPSS %2

    webmin · webmin29 Ara 2020

  • CVE-2021-32157
    39İzleyin

    A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.

    KritikCVSS 9,6Kavram kanıtıEPSS %4

    webmin · webmin11 Nis 2022

  • CVE-2019-9624
    38İzleyin

    Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges to

    YüksekCVSS 7,8SilahlaştırılmışEPSS %24

    webmin · webmin7 Mar 2019

  • CVE-2021-31762
    38İzleyin

    Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a

    YüksekCVSS 8,8Kavram kanıtıEPSS %9

    webmin · webmin25 Nis 2021

  • CVE-2021-31760
    38İzleyin

    Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to achieve Remote Command Execution (RCE) through Webmin's running process fea

    YüksekCVSS 8,8Kavram kanıtıEPSS %8

    webmin · webmin25 Nis 2021

  • CVE-2002-2360
    38İzleyin

    The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to ar

    KritikCVSS 9,3Kavram kanıtıEPSS %4

    webmin · webmin31 Ara 2002

  • CVE-2017-15644
    37İzleyin

    SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:80

    YüksekCVSS 8,6Kavram kanıtıEPSS %9

    webmin · webmin19 Eki 2017

  • CVE-2007-5066
    37İzleyin

    Unspecified vulnerability in Webmin before 1.370 on Windows allows remote authenticated users to execute arbitrary commands via a crafted UR

    KritikCVSS 9,0İstismar yokEPSS %2

    webmin · webmin24 Eyl 2007

  • CVE-2022-30708
    36İzleyin

    Webmin through 1.991, when the Authentic theme is used, allows remote code execution when a user has been manually created (i.e., not create

    YüksekCVSS 8,8İstismar yokEPSS %4

    webmin · webmin14 May 2022

  • CVE-2017-15645
    36İzleyin

    CSRF exists in Webmin 1.850.

    YüksekCVSS 8,8Kavram kanıtıEPSS %3

    webmin · webmin19 Eki 2017