8.8
CVSSv3

CVE-2020-35606

Published: 21/12/2020 Updated: 26/04/2022
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 802
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

Arbitrary command execution can occur in Webmin up to and including 1.962. Any user authorized for the Package Updates module can execute arbitrary commands with root privileges via vectors involving %0A and %0C. NOTE: this issue exists because of an incomplete fix for CVE-2019-12840.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

webmin webmin

Exploits

This Metasploit module exploits an arbitrary command execution vulnerability in Webmin 1962 and lower versions Any user authorized to the Package Updates module can execute arbitrary commands with root privileges It emerged by circumventing the measure taken for CVE-2019-12840 ...

Github Repositories

vulfocus-spring-boot-starter Chinese document Vulfocus API Vulfocus API is the RESUFul API interface provided by Vulfocus for development, allowing Developers integrate Vulfocus in their own projects Vulfocus SDK The Spring Boot version of SDK written based on the Vulfocus API makes it easy for Spring Boot developers to quickly integrate Vulfocus into their projects Add d

vulfocus-py Chinese document Vulfocus API Vulfocus API is the RESUFul API interface provided by Vulfocus for development, allowing Developers integrate Vulfocus in their own projects Vulfocus SDK The Python version of SDK written based on the Vulfocus API makes it easy for Python developers to quickly integrate Vulfocus into their projects Install pip install vulfocus USE

vulfocus-java Chinese document Vulfocus API Vulfocus API is the RESUFul API interface provided by Vulfocus for development, allowing Developers integrate Vulfocus in their own projects Vulfocus SDK The Java version of SDK written based on the Vulfocus API makes it easy for Java developers to quickly integrate Vulfocus into their projects Add dependency Apache Maven &l

Webmin Exploit Scanner CVE-2020-35606 CVE-2019-12840

Webminscan Webmin Exploit Scanner CVE-2020-35606 CVE-2019-12840