E19-5oon1
CVSS:
6.8 (AV:N/AC:L/Au:S/C:C/I:N/A:N)
False Positive:
t
Variants:
2
Year:
2018
Description
This strike exploits a cross-site scripting vulnerability in Webmin. The vulnerability results from the lack of sanitization when displaying the POST parameter history in /shell/index.cgi. A successful exploitation leads to arbitrary code execution in visitors browsers or credentials theft.
CVE
References
MSB
BID
ExploitDB
Secunia
Security Tracker
Metasploit
ZDI
OSVDB
{}