CVE-2022-0824
Improper Access Control to Remote Code Execution in webmin/webmin
Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Produtos afetados
webmin · webmin/webminPoCs públicas encontradas — 7
githubgithub.com/faisalfs10x/Webmin-CVE-2022-0824-revshell★ 111githubgithub.com/pizza-power/golang-webmin-CVE-2022-0824-revshell★ 3githubgithub.com/gokul-ramesh/WebminRCE-exploit★ 0githubgithub.com/NUDTTAN91/Webmin-CVE-2022-0824-Enhanced-Exploit★ 0cve_referencepacketstormsecurity.com/files/169700/Webmin-1.984-File-Manager-Remote-Code-Execution.htmlnão verificadocve_referencepacketstormsecurity.com/files/166240/Webmin-1.984-Remote-Code-Execution.htmlnão verificadoexploitdbwww.exploit-db.com/exploits/50809não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://packetstormsecurity.com/files/166240/Webmin-1.984-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/169700/Webmin-1.984-File-Manager-Remote-Code-Execution.htmlhttps://github.com/webmin/webmin/commit/39ea464f0c40b325decd6a5bfb7833fa4a142e38https://huntr.dev/bounties/d0049a96-de90-4b1a-9111-94de1044f295https://notes.netbytesec.com/2022/03/webmin-broken-access-control-to-post-auth-rce.html