Logo
vulnerabilityCVE-2020-35606
Name
CVE-2020-35606
Source
NVD ( link)Debian ( link)
Description
Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can execute arbitrary commands with root privileges via vectors involving %0A and %0C. NOTE: this issue exists because of an incomplete fix for CVE-2019-12840.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
webmin
Exploitable

Vulnerability Ratings#


8.8
CVSSv31
9
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
yocto
kirkstone
1.850
Exploitable
yocto
master
2.641
Not Affected