Vulnerability index

Browse CVEs

81 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Webmin CRITICAL 9.8
CVE-2019-15107 KEVEPSS 100%

An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.

Fix: after 1.920
Fix from $2,300 2019-08-16
Webmin HIGH 8.8
CVE-2019-12840EPSS 78%

In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data paramet…

Fix: after 1.910
Fix from $1,950 2019-06-15
Webmin MEDIUM 5.4
CVE-2018-19191EPSS 39%

Webmin 1.890 has XSS via /config.cgi?webmin, the /shell/index.cgi history parameter, /shell/index.cgi?stripped=1, or the /webminlog/search.cgi uall o…

No fix yet
Fix from $1,600 2019-03-21
Webmin HIGH 7.8
CVE-2019-9624EPSS 24%

Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges to upload a…

No fix yet
Fix from $1,950 2019-03-07
Webmin CRITICAL 9.8
CVE-2018-8712

An issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is enabled. As a result of weak d…

Mitigation only
Fix from $2,300 2018-03-14
Webmin HIGH 8.8
CVE-2017-15645

CSRF exists in Webmin 1.850. By sending a GET request to at/create_job.cgi containing dir=/&cmd= in the URI, an attacker to execute arbitrary command…

Fix: after 1.850
Fix from $1,950 2017-10-19
Webmin HIGH 8.6
CVE-2017-15644EPSS 9%

SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:8000.

Fix: after 1.850
Fix from $1,950 2017-10-19
Webmin MEDIUM 6.1
CVE-2017-15646

Webmin before 1.860 has XSS with resultant remote code execution. Under the 'Others/File Manager' menu, there is a 'Download from remote URL' option …

Fix: after 1.850
Fix from $1,600 2017-10-19
Webmin MEDIUM 6.1
CVE-2017-9313

Multiple Cross-site scripting (XSS) vulnerabilities in Webmin before 1.850 allow remote attackers to inject arbitrary web script or HTML via the sec …

Fix: after 1.840
Fix from $1,600 2017-07-04
Webmin MEDIUM 6.1
CVE-2017-2106

Multiple cross-site scripting vulnerabilities in Webmin versions prior to 1.830 allows remote attackers to inject arbitrary web script or HTML via un…

Fix: after 1.820
Fix from $1,600 2017-04-28
Usermin MEDIUM 6.1
CVE-2016-4897

Multiple cross-site scripting (XSS) vulnerabilities in (1) filter/save_forward.cgi, (2) filter/save.cgi, (3) /man/search.cgi in Usermin before 1.690.

Fix: after 1.680
Fix from $1,600 2017-04-12
Usermin MEDIUM 6.8
CVE-2014-3883

Usermin before 1.600 allows remote attackers to execute arbitrary operating-system commands via unspecified vectors related to a user action.

Fix: after 1.590
Fix from $1,600 2014-06-21
Webmin HIGH 9.0
CVE-2007-5066

Unspecified vulnerability in Webmin before 1.370 on Windows allows remote authenticated users to execute arbitrary commands via a crafted URL.

Fix: after 1.360
Fix from $1,950 2007-09-24
Webmin MEDIUM 5.0
CVE-2006-3274

Directory traversal vulnerability in Webmin before 1.280, when run on Windows, allows remote attackers to read arbitrary files via \ (backslash) char…

Fix: after 1.2.70
Fix from $1,600 2006-06-28
Webmin MEDIUM 5.0
CVE-2004-0582

Unknown vulnerability in Webmin 1.140 allows remote attackers to bypass access control rules and gain read access to configuration information for a …

Patch available
Fix from $1,600 2004-08-06
Webmin HIGH 10.0
CVE-2002-2201

The Printer Administration module for Webmin 0.990 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the …

Fix: after 0.99
Fix from $1,950 2002-12-31
Webmin HIGH 9.3
CVE-2002-2360

The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to arbitrary f…

No fix yet
Fix from $1,950 2002-12-31
Webmin MEDIUM 6.4
CVE-2002-1947

Webmin 0.21 through 1.0 uses the same built-in SSL key for all installations, which allows remote attackers to eavesdrop or highjack the SSL session.

Patch available
Fix from $1,600 2002-12-31
Webmin HIGH 10.0
CVE-2001-1196EPSS 10%

Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in the argumen…

Patch available
Fix from $1,950 2001-12-17
Webmin HIGH 7.2
CVE-2001-1074

Webmin 0.84 and earlier does not properly clear the HTTP_AUTHORIZATION environment variable when the web server is restarted, which makes authenticat…

Patch available
Fix from $1,950 2001-05-28
Webmin HIGH 7.5
CVE-1999-1074

Webmin before 0.5 does not restrict the number of invalid passwords that are entered for a valid username, which could allow remote attackers to gain…

Patch available
Fix from $1,950 1999-12-31