VDB
CVE-2019-15107
CVE-2019-15107
PUBLISHED
KEV
CVSS 10 CRITICAL
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.
EPSS 94.46% · 100.0th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
94.46%
100.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| webmin | webmin | 0 |
Timeline
- Aug 12, 2019 PoC Published
- Aug 16, 2019 CVE Published
- Aug 18, 2019 PoC Published
- Aug 19, 2019 PoC Published
- Aug 23, 2019 PoC Published
- Aug 27, 2019 PoC Published
- Jan 14, 2020 PoC Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
References
- https://nvd.nist.gov/vuln/detail/CVE-2019-15107 advisory
- http://www.webmin.com/security.html url
- https://www.exploit-db.com/exploits/47230 url
- http://www.pentest.com.tr/exploits/DEFCON-Webmin-1920-Unauthenticated-Remote-Command-Execution.html url
- http://packetstormsecurity.com/files/154141/Webmin-Remote-Comman-Execution.html url
- http://packetstormsecurity.com/files/154141/Webmin-1.920-Remote-Command-Execution.html url
- http://packetstormsecurity.com/files/154197/Webmin-1.920-password_change.cgi-Backdoor.html url
- http://packetstormsecurity.com/files/154485/Webmin-1.920-Remote-Code-Execution.html url
- https://attackerkb.com/topics/hxx3zmiCkR/webmin-password-change-cgi-command-injection url
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-15107 url