Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
webmin webmin vulnerabilities and exploits
(subscribe to this query)
1000
VMScore
CVE-2019-15107
An issue exists in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.
Webmin Webmin
1 EDB exploit
49 Github repositories
1 Article
1000
VMScore
CVE-2003-0101
miniserv.pl in (1) Webmin prior to 1.070 and (2) Usermin prior to 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded strings during Basic authentication, which allows remote malicious users to spoof a session ID and gai...
Usermin Usermin 0.6
Usermin Usermin 0.7
Usermin Usermin 0.96
Usermin Usermin 0.97
Usermin Usermin 0.4
Usermin Usermin 0.5
Usermin Usermin 0.93
Usermin Usermin 0.94
Usermin Usermin 0.95
Usermin Usermin 0.8
Usermin Usermin 0.9
Usermin Usermin 0.98
Usermin Usermin 0.99
Engardelinux Guardian Digital Webtool 1.2
Usermin Usermin 0.91
Usermin Usermin 0.92
Webmin Webmin 1.0.50
Webmin Webmin 1.0.60
1 EDB exploit
1000
VMScore
CVE-2001-1196
Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows malicious users to gain privileges via a '..' (dot dot) in the argument.
Webmin Webmin 0.91
1 EDB exploit
935
VMScore
CVE-2002-2360
The RPC module in Webmin 0.21 up to and including 0.99, when installed without root or admin privileges, allows remote malicious users to read and write to arbitrary files and execute arbitrary commands via remote_foreign_require and remote_foreign_call requests.
Webmin Webmin 0.41
Webmin Webmin 0.51
Webmin Webmin 0.88
Webmin Webmin 0.92
Webmin Webmin 0.970
Webmin Webmin 0.990
Webmin Webmin 0.21
Webmin Webmin 0.22
Webmin Webmin 0.31
Webmin Webmin 0.93
Webmin Webmin 0.94
Webmin Webmin 0.950
Webmin Webmin 0.960
Webmin Webmin 0.77
Webmin Webmin 0.78
Webmin Webmin 0.79
Webmin Webmin 0.80
Webmin Webmin 0.42
Webmin Webmin 0.76
Webmin Webmin 0.85
Webmin Webmin 0.91
Webmin Webmin 0.980
1 EDB exploit
890
VMScore
CVE-2011-5322
GE Healthcare Centricity Analytics Server 1.1 has a default password of (1) V0yag3r for the SQL Server sa user, (2) G3car3s for the analyst user, (3) G3car3s for the ccg user, (4) V0yag3r for the viewer user, and (5) geservice for the geservice user in the Webmin interface, which...
Gehealthcare Centricity Analytics Server 1.1
890
VMScore
CVE-2005-1177
Unknown vulnerability in (1) Webmin and (2) Usermin prior to 1.200 causes Webmin to change permissions and ownership of configuration files, with unknown impact.
Usermin Usermin 0.8
Usermin Usermin 0.9
Usermin Usermin 0.98
Usermin Usermin 0.99
Usermin Usermin 1.060
Usermin Usermin 1.070
Usermin Usermin 1.140
Webmin Webmin 0.4
Webmin Webmin 0.93
Webmin Webmin 0.94
Webmin Webmin 1.0.10
Webmin Webmin 1.0.20
Webmin Webmin 1.0.90
Webmin Webmin 1.1.00
Usermin Usermin 0.4
Usermin Usermin 0.5
Usermin Usermin 0.93
Usermin Usermin 0.94
Usermin Usermin 1.020
Usermin Usermin 1.030
Usermin Usermin 1.100
Usermin Usermin 1.110
890
VMScore
CVE-2002-2201
The Printer Administration module for Webmin 0.990 and previous versions allows remote malicious users to execute arbitrary commands via shell metacharacters in the printer name.
Webmin Webmin
805
VMScore
CVE-2019-12840
In Webmin up to and including 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data parameter to update.cgi.
Webmin Webmin
12 Github repositories
803
VMScore
CVE-2022-0824
Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin before 1.990.
Webmin Webmin
6 Github repositories
802
VMScore
CVE-2020-35606
Arbitrary command execution can occur in Webmin up to and including 1.962. Any user authorized for the Package Updates module can execute arbitrary commands with root privileges via vectors involving %0A and %0C. NOTE: this issue exists because of an incomplete fix for CVE-2019-1...
Webmin Webmin
4 Github repositories
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »