Webmin RPC Function Privilege...

- AV AC AU C I A
发布: 2002-08-28
修订: 2025-04-13

In cases where users of Webmin do not have root access on the underlying host, it may be possible to mount privilege escalation attacks on the underlying host. This normally occurs in configurations where multiple Webmin client systems have access to a centralized Webmin server. Webmin allows commands to be executed remotely on the underlying host from other Webmin client systems via the RPC module. However, the script that provides this facility does not sufficiently check the permissions of the source of the remote commands. As a result, it is possible for remote authenticated Webmin users to abuse this facility to execute commands (as root) on the underlying host. This may be exploited to gain root access to a system hosting the vulnerable software.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息