Webmin Local File Include (unauthenticated)# CVE-2021-42913
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes such as "%01" are removed from the filename.
[4.0K] /data/pocs/e25153601298249663ba8acf257c20e7634a91af
├── [ 619] exploit.py
└── [ 315] README.md
0 directories, 2 files