Vulnerability index

Browse CVEs

81 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2019-15107 KEVEPSS 100% An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability. Webmin after 1.920 Fix from $2,3002019-08-16 HIGH 8.8 CVE-2019-12840EPSS 78% In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data paramet… Webmin after 1.910 Fix from $1,9502019-06-15 MEDIUM 5.4 CVE-2018-19191EPSS 39% Webmin 1.890 has XSS via /config.cgi?webmin, the /shell/index.cgi history parameter, /shell/index.cgi?stripped=1, or the /webminlog/search.cgi uall o… Webmin No fix yet Fix from $1,6002019-03-21 HIGH 7.8 CVE-2019-9624EPSS 24% Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges to upload a… Webmin No fix yet Fix from $1,9502019-03-07 CRITICAL 9.8 CVE-2018-8712 An issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is enabled. As a result of weak d… Webmin Mitigation only Fix from $2,3002018-03-14 HIGH 8.8 CVE-2017-15645 CSRF exists in Webmin 1.850. By sending a GET request to at/create_job.cgi containing dir=/&cmd= in the URI, an attacker to execute arbitrary command… Webmin after 1.850 Fix from $1,9502017-10-19 HIGH 8.6 CVE-2017-15644EPSS 9% SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:8000. Webmin after 1.850 Fix from $1,9502017-10-19 MEDIUM 6.1 CVE-2017-15646 Webmin before 1.860 has XSS with resultant remote code execution. Under the 'Others/File Manager' menu, there is a 'Download from remote URL' option … Webmin after 1.850 Fix from $1,6002017-10-19 MEDIUM 6.1 CVE-2017-9313 Multiple Cross-site scripting (XSS) vulnerabilities in Webmin before 1.850 allow remote attackers to inject arbitrary web script or HTML via the sec … Webmin after 1.840 Fix from $1,6002017-07-04 MEDIUM 6.1 CVE-2017-2106 Multiple cross-site scripting vulnerabilities in Webmin versions prior to 1.830 allows remote attackers to inject arbitrary web script or HTML via un… Webmin after 1.820 Fix from $1,6002017-04-28 MEDIUM 6.1 CVE-2016-4897 Multiple cross-site scripting (XSS) vulnerabilities in (1) filter/save_forward.cgi, (2) filter/save.cgi, (3) /man/search.cgi in Usermin before 1.690. Usermin after 1.680 Fix from $1,6002017-04-12 MEDIUM 6.8 CVE-2014-3883 Usermin before 1.600 allows remote attackers to execute arbitrary operating-system commands via unspecified vectors related to a user action. Usermin after 1.590 Fix from $1,6002014-06-21 HIGH 9.0 CVE-2007-5066 Unspecified vulnerability in Webmin before 1.370 on Windows allows remote authenticated users to execute arbitrary commands via a crafted URL. Webmin after 1.360 Fix from $1,9502007-09-24 MEDIUM 5.0 CVE-2006-3274 Directory traversal vulnerability in Webmin before 1.280, when run on Windows, allows remote attackers to read arbitrary files via \ (backslash) char… Webmin after 1.2.70 Fix from $1,6002006-06-28 MEDIUM 5.0 CVE-2004-0582 Unknown vulnerability in Webmin 1.140 allows remote attackers to bypass access control rules and gain read access to configuration information for a … Webmin Patch available Fix from $1,6002004-08-06 HIGH 10.0 CVE-2002-2201 The Printer Administration module for Webmin 0.990 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the … Webmin after 0.99 Fix from $1,9502002-12-31 HIGH 9.3 CVE-2002-2360 The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to arbitrary f… Webmin No fix yet Fix from $1,9502002-12-31 MEDIUM 6.4 CVE-2002-1947 Webmin 0.21 through 1.0 uses the same built-in SSL key for all installations, which allows remote attackers to eavesdrop or highjack the SSL session. Webmin Patch available Fix from $1,6002002-12-31 HIGH 10.0 CVE-2001-1196EPSS 10% Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in the argumen… Webmin Patch available Fix from $1,9502001-12-17 HIGH 7.2 CVE-2001-1074 Webmin 0.84 and earlier does not properly clear the HTTP_AUTHORIZATION environment variable when the web server is restarted, which makes authenticat… Webmin Patch available Fix from $1,9502001-05-28 HIGH 7.5 CVE-1999-1074 Webmin before 0.5 does not restrict the number of invalid passwords that are entered for a valid username, which could allow remote attackers to gain… Webmin Patch available Fix from $1,9501999-12-31