Webmin是一套基于Web的用于类Unix操作系统中的系统管理工具。 Webmin 1.920及之前版本中的password_change.cgi存在命令操作系统命令注入漏洞。该漏洞源于外部输入数据构造可执行命令过程中,网络系统或产品未正确过滤其中的特殊元素。攻击者可利用该漏洞执行非法命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2019-15107 Webmin RCE (unauthorized) | https://github.com/jas502n/CVE-2019-15107 | POC Details |
| 2 | Dockerfiles for CVE-2019-15107(webmin RCE) recurrence including v1.890 and v1.920 with Exp for each version. | https://github.com/HACHp1/webmin_docker_and_exp | POC Details |
| 3 | Implementation of CVE-2019-15107 exploit in python | https://github.com/ketlerd/CVE-2019-15107 | POC Details |
| 4 | CVE-2019-15107 webmin python3 | https://github.com/AdministratorGithub/CVE-2019-15107 | POC Details |
| 5 | Built a custom Virtual Machine, running Ubuntu 18.04.1 and Webmin 1.810. Using CVE-2019-15107 to exploit a backdoor in the Linux machine | https://github.com/Rayferrufino/Make-and-Break | POC Details |
| 6 | Remote Code Execution Vulnerability in Webmin | https://github.com/AleWong/WebminRCE-EXP-CVE-2019-15107- | POC Details |
| 7 | None | https://github.com/ianxtianxt/CVE-2019-15107 | POC Details |
| 8 | poc exploit for webmin backdoor (CVE-2019-15107 and CVE-2019-15231) | https://github.com/hannob/webminex | POC Details |
| 9 | webmin_CVE-2019-15107 | https://github.com/ChakoMoonFish/webmin_CVE-2019-15107 | POC Details |
| 10 | None | https://github.com/cdedmondson/Modified-CVE-2019-15107 | POC Details |
| 11 | Webmin <=1.920 RCE | https://github.com/ruthvikvegunta/CVE-2019-15107 | POC Details |
| 12 | CVE-2019-15107 exploit | https://github.com/n0obit4/Webmin_1.890-POC | POC Details |
| 13 | CVE-2019–15107 - Unauthenticated RCE Webmin <=1.920 | https://github.com/squid22/Webmin_CVE-2019-15107 | POC Details |
| 14 | None | https://github.com/MuirlandOracle/CVE-2019-15107 | POC Details |
| 15 | None | https://github.com/diegojuan/CVE-2019-15107 | POC Details |
| 16 | CVE-2019-15107 Webmin Exploit in C | https://github.com/whokilleddb/CVE-2019-15107 | POC Details |
| 17 | None | https://github.com/puckiestyle/CVE-2019-15107 | POC Details |
| 18 | Something I wrote for CVE-2019-15107, a Webmin backdoor | https://github.com/darrenmartyn/CVE-2019-15107 | POC Details |
| 19 | Exploit para CVE-2019-15107 (Webmin 1.890-1.920) sin credenciales RCE escrito en PYTHON. | https://github.com/hacknotes/CVE-2019-15107-Exploit | POC Details |
| 20 | None | https://github.com/Tuz-Wwsd/CVE-2019-15107_detection | POC Details |
| 21 | CVE-2019-15107 Webmin 1.920 RCE | https://github.com/hadrian3689/webmin_1.920 | POC Details |
| 22 | CVE-2019-15107 | https://github.com/f0rkr/CVE-2019-15107 | POC Details |
| 23 | unauthorized RcE exploit for webnin < 1.920 | https://github.com/psw01/CVE-2019-15107_webminRCE | POC Details |
| 24 | Python3 code to exploit CVE-2019-15107 and CVE-2019-15231 | https://github.com/lolminerxmrig/CVE-2019-15107 | POC Details |
| 25 | WebMin Versions <= 1.920 [CVE-2019-15107] RCE PoC | https://github.com/TheAlpha19/MiniExploit | POC Details |
| 26 | CVE-2019-15107 图形化测试程序 | https://github.com/wenruoya/CVE-2019-15107 | POC Details |
| 27 | webmin <=1.920 - RCE via command injection vulnerability | https://github.com/g1vi/CVE-2019-15107 | POC Details |
| 28 | A PoC exploit for CVE-2019-1510 - Webmin Command Injection. | https://github.com/K3ysTr0K3R/CVE-2019-15107-EXPLOIT | POC Details |
| 29 | school project | https://github.com/gozn/detect-CVE-2019-15107-by-pyshark | POC Details |
| 30 | None | https://github.com/h4ck0rman/CVE-2019-15107 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2017-18544 | WordPress invite-anyone插件跨站请求伪造漏洞 | |
| CVE-2014-10376 | WordPress i-recommend-this插件SQL注入漏洞 | |
| CVE-2015-9324 | WordPress easy-digital-downloads插件SQL注入漏洞 | |
| CVE-2019-15116 | WordPress easy-digital-downloads插件跨站脚本漏洞 | |
| CVE-2015-9323 | WordPress 404-to-301插件SQL注入漏洞 | |
| CVE-2019-15115 | WordPress peters-login-redirect插件跨站请求伪造漏洞 | |
| CVE-2017-18547 | WordPress nelio-ab-testing插件跨站请求伪造漏洞 | |
| CVE-2018-20974 | WordPress js-jobs插件跨站请求伪造漏洞 | |
| CVE-2017-18546 | WordPress jayj-quicktag插件跨站请求伪造漏洞 | |
| CVE-2017-18545 | WordPress invite-anyone插件输入验证错误漏洞 | |
| CVE-2019-15120 | Kunena extension for Joomla! 跨站脚本漏洞 | |
| CVE-2017-18543 | WordPress invite-anyone插件访问控制错误漏洞 | |
| CVE-2019-15114 | WordPress formcraft-form-builder插件跨站请求伪造漏洞 | |
| CVE-2015-9322 | WordPress erident-custom-login-and-dashboard插件跨站请求伪造漏洞 | |
| CVE-2019-15113 | WordPress companion-sitemap-generator插件跨站请求伪造漏洞 | |
| CVE-2018-20973 | WordPress companion-auto-update插件输入验证错误漏洞 | |
| CVE-2018-20972 | WordPress companion-auto-update插件跨站请求伪造漏洞 | |
| CVE-2018-20971 | WordPress church-admin插件跨站请求伪造漏洞 | |
| CVE-2017-18542 | WordPress zendesk-help-center插件跨站脚本漏洞 | |
| CVE-2017-18541 | WordPress xo-security插件跨站脚本漏洞 |
Showing top 20 of 40 CVEs. View all on vendor page → →
No comments yet