CVE-2022-0824 – Improper Access Control to Remote Code Execution in webmin/webmin
https://notcve.org/view.php?id=CVE-2022-0824
Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990. Un Control de Acceso Inapropiado para una Ejecución de Código Remota en el repositorio de GitHub webmin/webmin versiones anteriores a 1.990 • https://www.exploit-db.com/exploits/50809 https://github.com/faisalfs10x/Webmin-CVE-2022-0824-revshell https://github.com/pizza-power/golang-webmin-CVE-2022-0824-revshell https://github.com/honypot/CVE-2022-0824 http://packetstormsecurity.com/files/166240/Webmin-1.984-Remote-Code-Execution.html http://packetstormsecurity.com/files/169700/Webmin-1.984-File-Manager-Remote-Code-Execution.html https://github.com/webmin/webmin/commit/39ea464f0c40b325decd6a5bfb7833fa4a142e38 https://huntr.dev/bounties/d0049a96-de • CWE-284: Improper Access Control CWE-863: Incorrect Authorization •
CVE-2021-31762 – Webmin 1.973 - 'save_user.cgi' Cross-Site Request Forgery (CSRF)
https://notcve.org/view.php?id=CVE-2021-31762
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a reverse shell through Webmin's running process feature. Webmin versión 1.973, esta afectado por una vulnerabilidad de tipo Cross Site Request Forgery (CSRF) para crear un usuario privilegiado mediante la funcionalidad Webmin's add users, y luego obtener un shell inverso mediante la funcionalidad Webmin's running process Webmin version 1.973 suffers from a cross site request forgery vulnerability. • https://www.exploit-db.com/exploits/50126 https://github.com/electronicbots/CVE-2021-31762 https://github.com/Mesh3l911/CVE-2021-31762 http://packetstormsecurity.com/files/163492/Webmin-1.973-Cross-Site-Request-Forgery.html https://github.com/webmin/webmin https://youtu.be/qCvEXwyaF5U • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2021-31761 – Webmin 1.973 - 'run.cgi' Cross-Site Request Forgery (CSRF)
https://notcve.org/view.php?id=CVE-2021-31761
Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process feature. Webmin versión 1.973, esta afectado por una vulnerabilidad de tipo Cross Site Scripting (XSS) reflejado para lograr una ejecución de comandos remota por medio de la funcionalidad Webmin's running process • https://www.exploit-db.com/exploits/50144 https://github.com/electronicbots/CVE-2021-31761 https://github.com/Mesh3l911/CVE-2021-31761 http://packetstormsecurity.com/files/163559/Webmin-1.973-Cross-Site-Request-Forgery.html https://github.com/webmin/webmin https://youtu.be/23VvUMu-28c • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-31760
https://notcve.org/view.php?id=CVE-2021-31760
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to achieve Remote Command Execution (RCE) through Webmin's running process feature. Webmin versión 1.973, esta afectado por una vulnerabilidad de tipo Cross Site Request Forgery (CSRF) para lograr una Ejecución de Comandos Remota (RCE) por medio de la funcionalidad Webmin's running process • https://github.com/electronicbots/CVE-2021-31760 https://github.com/Mesh3l911/CVE-2021-31760 https://github.com/webmin/webmin https://youtu.be/D45FN8QrzDo • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2020-35769
https://notcve.org/view.php?id=CVE-2020-35769
miniserv.pl in Webmin 1.962 on Windows mishandles special characters in query arguments to the CGI program. El archivo miniserv.pl en Webmin versión 1.962 en Windows, maneja inapropiadamente unos caracteres especiales en los argumentos de consulta para el programa CGI • https://github.com/webmin/webmin/commit/1163f3a7f418f249af64890f4636575e687e9de7#diff-9b33fd8f5603d4f0d1428689bc36f24af4770608a22c0d92b7a8bcc522450dc6 https://vigilance.fr/vulnerability/Webmin-code-execution-via-miniserv-pl-handle-request-34220 •