Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the Java file manager and Upload and Download privileges to upload a crafted .cgi file via the /updown/upload.cgi URI.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Webmin | Webmin | 1.900 (including) | 1.900 (including) |