Webmin Package Updates Command Injection

Discussion in 'News Aggregator' started by Packet Storm, 11 Aug 2022.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module exploits an arbitrary command injection in Webmin versions prior to 1.997. Webmin uses the OS package manager (apt, yum, etc.) to perform package updates and installation. Due to a lack of input sanitization, it is possible to inject an arbitrary command that will be concatenated to the package manager call. This exploit requires authentication and the account must have access to the Software Package Updates module.

    Continue reading...
     
  2. jonny jonnywellium

    Joined:
    10 Aug 2022
    Messages:
    2
    Likes Received:
    0
    I agree It is possible to insert an arbitrary command that will be concatenated to the package management call due to a lack of input sanitization.
    The account must be authenticated for this attack and have permission to the Software Package Updates module.
     

Share This Page

Loading...