Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
工具/GitHubGitHub/n0obit4/webmin_1.890-poc
漏洞分析漏洞利用Web应用程序漏洞利用渗透测试命令与控制远程访问工具
GitHubn0obit4/webmin_1.890-poc

Webmin_1.890-POC

CVE-2019-15107 漏洞利用

查看仓库
7215年前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

Webmin 1.890 过期密码远程 Root 漏洞

CVE-2019-15107

Webmin 版本 1.890 发布时携带一个后门,任何知晓该后门的人都可以以 root 身份执行命令。版本 1.900 到 1.920 也包含使用类似代码的后门,但在默认的 Webmin 安装中无法被利用。只有当管理员在 Webmin -> Webmin 配置 -> 身份验证 中启用了允许更改过期密码的功能时,攻击者才能利用它。

要求

你需要 pip3 来安装这些软件包。

  • requests
  • argparse
  • os
  • bs4

帮助菜单

$ python3 Webmin_exploit.py --help
usage: Webmin_exploit.py [-h] -host IP [-port Port] [-cmd Command]

Webmin 1.890 expired Remote Root POC

optional arguments:
  -h, --help    show this help message and exit
  -host IP      Host to attack
  -port Port    Port of the host ~ 10000 is Default
  -cmd Command  Command to execute ~ id is Default

python3 Webmin_exploit.py -host target -port 10000 -cmd id

用法

$ python3 Webmin_exploit.py -host target -port 10000 -cmd id

演示

[POC

下载工具