[mdlug] Be sure to update your Webmin

Gib gibmaxn at gmail.com
Mon Sep 2 20:46:30 EDT 2019


With over 3 million downloads per year, Webmin is one of the world's
most popular open-source web-based applications for managing
Unix-based systems, such as Linux, FreeBSD, or OpenBSD servers

According to the researcher, the security flaw resides in the password
reset page and allows a remote, unauthenticated attacker to execute
arbitrary commands with root privileges on affected servers just by
adding a simple pipe command ("|") in the old password field through
POST requests.

https://thehackernews.com/2019/08/webmin-vulnerability-hacking.html


More information about the mdlug mailing list