Webmin Package Updates Command Injection...

- AV AC AU C I A
发布: 2022-08-10
修订: 2024-10-05

This Metasploit module exploits an arbitrary command injection in Webmin versions prior to 1.997. Webmin uses the OS package manager (apt, yum, etc.) to perform package updates and installation. Due to a lack of input sanitization, it is possible to inject an arbitrary command that will be concatenated to the package manager call. This exploit requires authentication and the account must have access to the Software Package Updates module.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息