Webmin kayıtları
webmin üreticisine ait 112 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %0,9
- Silahlaştırılmış
- 6 · %5,4
- Pre-auth RCE
- 11
- Düzeltme kaydı olan
- %8,9
- Yayından KEV’e ortanca
- 953 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')56
- CWE-352 Cross-Site Request Forgery (CSRF)8
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')6
- CWE-284 Improper Access Control2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-269 Improper Privilege Management1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
112 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2019-15107Silahlaştırılmış | An issue was discovered in Webmin <=1.920.webmin · webmin · CWE-78 | Kritik9,8 | KEV | %99,7 | 15 Ağu 2019 |
68Bu hafta | CVE-2022-36446Silahlaştırılmış | software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.webmin · webmin · CWE-116 | Kritik9,8 | — | %96,0 | 25 Tem 2022 |
64Bu hafta | CVE-2022-0824Silahlaştırılmış | Improper Access Control to Remote Code Execution in webmin/webminwebmin · webmin · CWE-284 | Yüksek8,8 | — | %97,0 | 2 Mar 2022 |
58Planlayın | CVE-2019-12840Silahlaştırılmış | In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the datwebmin · webmin · CWE-78 | Yüksek8,8 | — | %77,8 | 15 Haz 2019 |
48Planlayın | CVE-2021-31761Kavram kanıtı | Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process featurwebmin · webmin · CWE-79 | Kritik9,6 | — | %33,6 | 25 Nis 2021 |
45Planlayın | CVE-2020-8821İstismar yok | An Improper Data Validation Vulnerability exists in Webmin 1.941 and earlier affecting the Command Shell Endpoint.webmin · webmin · CWE-79 | Orta5,4 | — | %80,2 | 12 Eki 2020 |
45Planlayın | CVE-2019-15642Kavram kanıtı | rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an ewebmin · webmin · CWE-94 | Yüksek8,8 | — | %34,8 | 26 Ağu 2019 |
45Planlayın | CVE-2024-12828Kavram kanıtı | Webmin CGI Command Injection Remote Code Execution Vulnerabilitywebmin · webmin · CWE-78 | Yüksek8,8 | — | %33,5 | 30 Ara 2024 |
45Planlayın | CVE-2003-0101Kavram kanıtı | miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage usermin · usermin | Kritik10,0 | — | %15,5 | 3 Mar 2003 |
43Planlayın | CVE-2006-3392Silahlaştırılmış | Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arusermin · usermin | Orta5,0 | — | %78,3 | 6 Tem 2006 |
43Planlayın | CVE-2020-35606Kavram kanıtı | Arbitrary command execution can occur in Webmin through 1.962.webmin · webmin · CWE-78 | Yüksek8,8 | — | %28,0 | 21 Ara 2020 |
43Planlayın | CVE-2001-1196Kavram kanıtı | Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in thwebmin · webmin | Kritik10,0 | — | %9,8 | 17 Ara 2001 |
41Planlayın | CVE-2002-2201İstismar yok | The Printer Administration module for Webmin 0.990 and earlier allows remote attackers to execute arbitrary commands via shell metacharacterwebmin · webmin | Kritik10,0 | — | %3,3 | 31 Ara 2002 |
41Planlayın | CVE-2005-1177İstismar yok | Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, wusermin · usermin | Kritik10,0 | — | %1,8 | 2 May 2005 |
40Planlayın | CVE-2018-8712İstismar yok | An issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is enabled.webmin · webmin · CWE-22 | Kritik9,8 | — | %1,8 | 14 Mar 2018 |
40Planlayın | CVE-2020-35769İstismar yok | miniserv.pl in Webmin 1.962 on Windows mishandles special characters in query arguments to the CGI program.webmin · webmin | Kritik9,8 | — | %1,8 | 29 Ara 2020 |
39İzleyin | CVE-2021-32157Kavram kanıtı | A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.webmin · webmin · CWE-79 | Kritik9,6 | — | %4,0 | 11 Nis 2022 |
38İzleyin | CVE-2019-9624Silahlaştırılmış | Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges towebmin · webmin · CWE-269 | Yüksek7,8 | — | %23,7 | 7 Mar 2019 |
38İzleyin | CVE-2021-31762Kavram kanıtı | Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get awebmin · webmin · CWE-352 | Yüksek8,8 | — | %8,8 | 25 Nis 2021 |
38İzleyin | CVE-2021-31760Kavram kanıtı | Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to achieve Remote Command Execution (RCE) through Webmin's running process feawebmin · webmin · CWE-352 | Yüksek8,8 | — | %8,5 | 25 Nis 2021 |
38İzleyin | CVE-2002-2360Kavram kanıtı | The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to arwebmin · webmin · CWE-264 | Kritik9,3 | — | %3,6 | 31 Ara 2002 |
37İzleyin | CVE-2017-15644Kavram kanıtı | SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:80webmin · webmin · CWE-918 | Yüksek8,6 | — | %8,9 | 19 Eki 2017 |
37İzleyin | CVE-2007-5066İstismar yok | Unspecified vulnerability in Webmin before 1.370 on Windows allows remote authenticated users to execute arbitrary commands via a crafted URwebmin · webmin · CWE-20 | Kritik9,0 | — | %2,4 | 24 Eyl 2007 |
36İzleyin | CVE-2022-30708İstismar yok | Webmin through 1.991, when the Authentic theme is used, allows remote code execution when a user has been manually created (i.e., not createwebmin · webmin | Yüksek8,8 | — | %3,6 | 14 May 2022 |
36İzleyin | CVE-2017-15645Kavram kanıtı | CSRF exists in Webmin 1.850.webmin · webmin · CWE-352 | Yüksek8,8 | — | %3,2 | 19 Eki 2017 |
- CVE-2019-1510799Hemen
An issue was discovered in Webmin <=1.920.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100webmin · webmin15 Ağu 2019
- CVE-2022-3644668Bu hafta
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
KritikCVSS 9,8SilahlaştırılmışEPSS %96webmin · webmin25 Tem 2022
- CVE-2022-082464Bu hafta
Improper Access Control to Remote Code Execution in webmin/webmin
YüksekCVSS 8,8SilahlaştırılmışEPSS %97webmin · webmin2 Mar 2022
- CVE-2019-1284058Planlayın
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the dat
YüksekCVSS 8,8SilahlaştırılmışEPSS %78webmin · webmin15 Haz 2019
- CVE-2021-3176148Planlayın
Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process featur
KritikCVSS 9,6Kavram kanıtıEPSS %34webmin · webmin25 Nis 2021
- CVE-2020-882145Planlayın
An Improper Data Validation Vulnerability exists in Webmin 1.941 and earlier affecting the Command Shell Endpoint.
OrtaCVSS 5,4İstismar yokEPSS %80webmin · webmin12 Eki 2020
- CVE-2019-1564245Planlayın
rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an e
YüksekCVSS 8,8Kavram kanıtıEPSS %35webmin · webmin26 Ağu 2019
- CVE-2024-1282845Planlayın
Webmin CGI Command Injection Remote Code Execution Vulnerability
YüksekCVSS 8,8Kavram kanıtıEPSS %33webmin · webmin30 Ara 2024
- CVE-2003-010145Planlayın
miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage
KritikCVSS 10,0Kavram kanıtıEPSS %15usermin · usermin3 Mar 2003
- CVE-2006-339243Planlayın
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read ar
OrtaCVSS 5,0SilahlaştırılmışEPSS %78usermin · usermin6 Tem 2006
- CVE-2020-3560643Planlayın
Arbitrary command execution can occur in Webmin through 1.962.
YüksekCVSS 8,8Kavram kanıtıEPSS %28webmin · webmin21 Ara 2020
- CVE-2001-119643Planlayın
Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in th
KritikCVSS 10,0Kavram kanıtıEPSS %10webmin · webmin17 Ara 2001
- CVE-2002-220141Planlayın
The Printer Administration module for Webmin 0.990 and earlier allows remote attackers to execute arbitrary commands via shell metacharacter
KritikCVSS 10,0İstismar yokEPSS %3webmin · webmin31 Ara 2002
- CVE-2005-117741Planlayın
Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, w
KritikCVSS 10,0İstismar yokEPSS %2usermin · usermin2 May 2005
- CVE-2018-871240Planlayın
An issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is enabled.
KritikCVSS 9,8İstismar yokEPSS %2webmin · webmin14 Mar 2018
- CVE-2020-3576940Planlayın
miniserv.pl in Webmin 1.962 on Windows mishandles special characters in query arguments to the CGI program.
KritikCVSS 9,8İstismar yokEPSS %2webmin · webmin29 Ara 2020
- CVE-2021-3215739İzleyin
A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.
KritikCVSS 9,6Kavram kanıtıEPSS %4webmin · webmin11 Nis 2022
- CVE-2019-962438İzleyin
Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges to
YüksekCVSS 7,8SilahlaştırılmışEPSS %24webmin · webmin7 Mar 2019
- CVE-2021-3176238İzleyin
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a
YüksekCVSS 8,8Kavram kanıtıEPSS %9webmin · webmin25 Nis 2021
- CVE-2021-3176038İzleyin
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to achieve Remote Command Execution (RCE) through Webmin's running process fea
YüksekCVSS 8,8Kavram kanıtıEPSS %8webmin · webmin25 Nis 2021
- CVE-2002-236038İzleyin
The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to ar
KritikCVSS 9,3Kavram kanıtıEPSS %4webmin · webmin31 Ara 2002
- CVE-2017-1564437İzleyin
SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:80
YüksekCVSS 8,6Kavram kanıtıEPSS %9webmin · webmin19 Eki 2017
- CVE-2007-506637İzleyin
Unspecified vulnerability in Webmin before 1.370 on Windows allows remote authenticated users to execute arbitrary commands via a crafted UR
KritikCVSS 9,0İstismar yokEPSS %2webmin · webmin24 Eyl 2007
- CVE-2022-3070836İzleyin
Webmin through 1.991, when the Authentic theme is used, allows remote code execution when a user has been manually created (i.e., not create
YüksekCVSS 8,8İstismar yokEPSS %4webmin · webmin14 May 2022
- CVE-2017-1564536İzleyin
CSRF exists in Webmin 1.850.
YüksekCVSS 8,8Kavram kanıtıEPSS %3webmin · webmin19 Eki 2017