Webmin Unauthenticated Remote Execution

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

## EDB-ID: 47230 ## CVE-2019-15107 10 Aug, 2019 • EXPLOIT This 0day has been published at @DEFCON AppSec Village Vendor fixed this vulnerability. [Webmin must update to the 1.930 version.](http://webmin.com/changes.html) [Exploit-DB Link](https://www.exploit-db.com/exploits/47230) [CVE-Mitre Link](https://nvd.nist.gov/vuln/detail/CVE-2019-15107) [Download defcon_webmin_unauth_rce.rb](https://pentest.com.tr/blog/defcon-0days-10102019/defcon_webmin_unauth_rce.rb) ## Webmin <= 1.920 - Unauthenticated RCE ``` ## # This module requires Metasploit: https://metasploit.com/download # Current source: https://github.com/rapid7/metasploit-framework ## class MetasploitModule < Msf::Exploit::Remote Rank = ExcellentRanking include Msf::Exploit::Remote::HttpClient def initialize(info = {}) super(update_info(info, 'Name' => 'Webmin 1.920 Unauthenticated RCE', 'Description' => %q( This module exploits an arbitrary command execution vulnerability in Webmin 1.920 and prior versions. If the password...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息