yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2019-15107
Component Overview
Vulnerability Overview
Name
CVE-2019-15107
Source
NVD (
link
)
Debian (
link
)
Description
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.
CWEs
CWE-78
CWE-78
Published Date
Aug 16, 2019
Updated Date
Jun 17, 2026
Workaround
-
Advisories
http://packetstormsecurity.com/files/154141/Webmin-1.920-Remote-Command-Execution.html
Exploit
http://packetstormsecurity.com/files/154141/Webmin-Remote-Comman-Execution.html
Exploit
http://packetstormsecurity.com/files/154197/Webmin-1.920-password_change.cgi-Backdoor.html
Exploit
http://packetstormsecurity.com/files/154485/Webmin-1.920-Remote-Code-Execution.html
VDB Entry
http://www.pentest.com.tr/exploits/DEFCON-Webmin-1920-Unauthenticated-Remote-Command-Execution.html
Exploit
http://www.webmin.com/security.html
Vendor Advisory
https://attackerkb.com/topics/hxx3zmiCkR/webmin-password-change-cgi-command-injection
Third Party Advisory
https://www.exploit-db.com/exploits/47230
Exploit
http://packetstormsecurity.com/files/154141/Webmin-1.920-Remote-Command-Execution.html
Exploit
http://packetstormsecurity.com/files/154141/Webmin-Remote-Comman-Execution.html
Exploit
http://packetstormsecurity.com/files/154197/Webmin-1.920-password_change.cgi-Backdoor.html
Exploit
http://packetstormsecurity.com/files/154485/Webmin-1.920-Remote-Code-Execution.html
VDB Entry
http://www.pentest.com.tr/exploits/DEFCON-Webmin-1920-Unauthenticated-Remote-Command-Execution.html
Exploit
http://www.webmin.com/security.html
Vendor Advisory
https://attackerkb.com/topics/hxx3zmiCkR/webmin-password-change-cgi-command-injection
Third Party Advisory
https://www.exploit-db.com/exploits/47230
Exploit
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-15107
US Government Resource
Analysis
#
Affected Component
Analysis
webmin
Exploitable
Vulnerability Ratings
#
9.8
CVSSv31
9.8
CVSSv31
10
CVSSv2
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
webmin
yocto
kirkstone
1.850
Exploitable
webmin
yocto
master
2.641
Not Affected