Show filters
101 Total Results
Displaying 1-10 of 101
Sort by:
Attacker Value
Unknown

CVE-2019-15107

Disclosure Date: August 16, 2019 (last updated December 06, 2023)
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.
Attacker Value
Unknown

CVE-2018-19191

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
Webmin 1.890 has XSS via /config.cgi?webmin, the /shell/index.cgi history parameter, /shell/index.cgi?stripped=1, or the /webminlog/search.cgi uall or mall parameter.
1
Attacker Value
Unknown

CVE-2024-12828

Disclosure Date: December 30, 2024 (last updated January 02, 2025)
Webmin CGI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Webmin. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of CGI requests. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-22346.
0
Attacker Value
Unknown

CVE-2024-45692

Disclosure Date: September 04, 2024 (last updated September 06, 2024)
Webmin before 2.202 and Virtualmin before 7.20.2 allow a network traffic loop via spoofed UDP packets on port 10000.
Attacker Value
Unknown

CVE-2024-36453

Disclosure Date: July 10, 2024 (last updated July 10, 2024)
Cross-site scripting vulnerability exists in session_login.cgi of Webmin versions prior to 1.970 and Usermin versions prior to 1.820. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a webpage may be altered or sensitive information such as a credential may be disclosed.
0
Attacker Value
Unknown

CVE-2024-36452

Disclosure Date: July 10, 2024 (last updated July 10, 2024)
Cross-site request forgery vulnerability exists in ajaxterm module of Webmin versions prior to 2.003. If this vulnerability is exploited, unintended operations may be performed when a user views a malicious page while logged in. As a result, data within a system may be referred, a webpage may be altered, or a server may be permanently halted.
0
Attacker Value
Unknown

CVE-2024-36451

Disclosure Date: July 10, 2024 (last updated July 10, 2024)
Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003. If this vulnerability is exploited, a console session may be hijacked by an unauthorized user. As a result, data within a system may be referred, a webpage may be altered, or a server may be permanently halted.
0
Attacker Value
Unknown

CVE-2024-36450

Disclosure Date: July 10, 2024 (last updated August 01, 2024)
Cross-site scripting vulnerability exists in sysinfo.cgi of Webmin versions prior to 1.910. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a session ID may be obtained, a webpage may be altered, or a server may be halted.
Attacker Value
Unknown

CVE-2023-52046

Disclosure Date: January 25, 2024 (last updated February 14, 2024)
Cross Site Scripting vulnerability (XSS) in webmin v.2.105 and earlier allows a remote attacker to execute arbitrary code via a crafted payload to the "Execute cron job as" tab Input field.
Attacker Value
Unknown

CVE-2023-43309

Disclosure Date: September 21, 2023 (last updated October 08, 2023)
There is a stored cross-site scripting (XSS) vulnerability in Webmin 2.002 and below via the Cluster Cron Job tab Input field, which allows attackers to run malicious scripts by injecting a specially crafted payload.