RULE(RULE ID:324345)

Rule General Information
Release Date: 2020-02-19
Rule Name: Webmin Remote Command Execution Vulnerability (CVE-2019-15107)
Severity:
CVE ID:
Rule Protection Details
Description: An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux
Reference: ExploitDB:47230
http://packetstormsecurity.com/files/154141/Webmin-1.920-Remote-Command-Execution.html
http://packetstormsecurity.com/files/154141/Webmin-Remote-Comman-Execution.html
http://packetstormsecurity.com/files/154197/Webmin-1.920-password_change.cgi-Backdoor.html
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www.webmin.com/