'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:CVE-2019-15107: Webmin 1.920 Remote Command Execution Vulnerability
Severity:critical
CVE ID:CVE-2019-15107
| Descripiton:
|
Webmin is a set of web-based system management tool for Unix operating system. The old parameter of password_change.cgi file in Webmin 1.920 and previous versions has a command injection vulnerability. The vulnerability originates from the process of external input data construction of executable command, and the tool fails to properly filter the special elements in it. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.