vendor:
Webmin
by:
Fernando A. Lagos B. (Zerial)
9.8
CVSS
CRITICAL
Remote Command Execution
78
CWE
Product Name: Webmin
Affected Version From: 1.910
Affected Version To: 1.920
Patch Exists: YES
Related CWE: CVE-2019-15107
CPE: a:webmin:webmin
Other Scripts:
N/A
Platforms Tested: Linux
2019
CVE-2019-15107 Webmin Unauhenticated Remote Command Execution
This vulnerability allows an unauthenticated attacker to execute arbitrary commands on the vulnerable system. It is based on a Metasploit module and was discovered by Fernando A. Lagos B. (Zerial). The exploit sends a flag by a echo command then grep it. If match, target is vulnerable.
Mitigation:
The user should upgrade to the latest version of Webmin and apply the patch provided by the vendor.