Show filters
109 Total Results
Displaying 1-10 of 109
Sort by:
Attacker Value
Unknown
CVE-2019-15107
Disclosure Date: August 16, 2019 (last updated December 06, 2023)
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.
3
Attacker Value
Unknown
CVE-2018-19191
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
Webmin 1.890 has XSS via /config.cgi?webmin, the /shell/index.cgi history parameter, /shell/index.cgi?stripped=1, or the /webminlog/search.cgi uall or mall parameter.
1
Attacker Value
Unknown
CVE-2024-12828
Disclosure Date: December 30, 2024 (last updated January 02, 2025)
Webmin CGI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Webmin. Authentication is required to exploit this vulnerability.
The specific flaw exists within the handling of CGI requests. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-22346.
0
Attacker Value
Unknown
CVE-2024-45692
Disclosure Date: September 04, 2024 (last updated September 06, 2024)
Webmin before 2.202 and Virtualmin before 7.20.2 allow a network traffic loop via spoofed UDP packets on port 10000.
0
Attacker Value
Unknown
CVE-2024-36453
Disclosure Date: July 10, 2024 (last updated July 10, 2024)
Cross-site scripting vulnerability exists in session_login.cgi of Webmin versions prior to 1.970 and Usermin versions prior to 1.820. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a webpage may be altered or sensitive information such as a credential may be disclosed.
0
Attacker Value
Unknown
CVE-2024-36452
Disclosure Date: July 10, 2024 (last updated July 10, 2024)
Cross-site request forgery vulnerability exists in ajaxterm module of Webmin versions prior to 2.003. If this vulnerability is exploited, unintended operations may be performed when a user views a malicious page while logged in. As a result, data within a system may be referred, a webpage may be altered, or a server may be permanently halted.
0
Attacker Value
Unknown
CVE-2024-36451
Disclosure Date: July 10, 2024 (last updated July 10, 2024)
Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003. If this vulnerability is exploited, a console session may be hijacked by an unauthorized user. As a result, data within a system may be referred, a webpage may be altered, or a server may be permanently halted.
0
Attacker Value
Unknown
CVE-2024-36450
Disclosure Date: July 10, 2024 (last updated August 01, 2024)
Cross-site scripting vulnerability exists in sysinfo.cgi of Webmin versions prior to 1.910. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a session ID may be obtained, a webpage may be altered, or a server may be halted.
0
Attacker Value
Unknown
CVE-2023-52046
Disclosure Date: January 25, 2024 (last updated February 14, 2024)
Cross Site Scripting vulnerability (XSS) in webmin v.2.105 and earlier allows a remote attacker to execute arbitrary code via a crafted payload to the "Execute cron job as" tab Input field.
0
Attacker Value
Unknown
CVE-2023-43309
Disclosure Date: September 21, 2023 (last updated October 08, 2023)
There is a stored cross-site scripting (XSS) vulnerability in Webmin 2.002 and below via the Cluster Cron Job tab Input field, which allows attackers to run malicious scripts by injecting a specially crafted payload.
0