Webmin Upload Authenticated RCE
cve CVE-2019-9624 2 sources, 2 claims · Watch
Metasploit exploit modules writes:
This module exploits an arbitrary command execution vulnerability in Webmin 1.900 and lower versions. Any user authorized to the "Upload and Download" module can execute arbitrary commands with root privileges. In addition, if the 'Running Processes' (proc) privilege is set the user can accurately determine which directory to upload to. Webmin application files can be written/overwritten, which allows remote code execution. The module has been tested successfully with Webmin 1.900 on Ubuntu v18.04. Using GUESSUPLOAD attemp… the claim
This module exploits an arbitrary command execution vulnerability in Webmin 1.900 and lower versions. Any user authorized to the "Upload and Download" module can execute arbitrary commands with root privileges. In addition, if the 'Running Processes' (proc) privilege is set the user can accurately determine which directory to upload to. Webmin application files can be written/overwritten, which allows remote code execution. The module has been tested successfully with Webmin 1.900 on Ubuntu v18.04. Using GUESSUPLOAD attemp… the claim
What each source says
| Property | Source | Said | Means here |
|---|---|---|---|
| Author author | Exploit-DB | AkkuSreceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "AkkuS",
"codes": "CVE-2019-9624",
"date_added": "2019-01-18",
"date_published": "2019-01-18",
"date_updated": "2019-03-08",
"description": "Webmin 1.900 - Remote Command Execution (Metasploit)",
"file": "exploits/cgi/remote/46201.rb",
"id": "46201",
"platform": "cgi",
"port": "10000",
"screenshot_url": "",
"source_url": "",
"tags": "Metasploit Framework (MSF)",
"type": "remote",
"verified": "0"
} | — |
| Platform platform not compared | Exploit-DB | cgireceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "AkkuS",
"codes": "CVE-2019-9624",
"date_added": "2019-01-18",
"date_published": "2019-01-18",
"date_updated": "2019-03-08",
"description": "Webmin 1.900 - Remote Command Execution (Metasploit)",
"file": "exploits/cgi/remote/46201.rb",
"id": "46201",
"platform": "cgi",
"port": "10000",
"screenshot_url": "",
"source_url": "",
"tags": "Metasploit Framework (MSF)",
"type": "remote",
"verified": "0"
} | — |
| Platform platform not compared | Metasploit exploit modules | Unixreceipt
What the source handed over{
"aliases": [],
"arch": "cmd",
"author": [
"AkkuS <Özkan Mustafa Akkuş>",
"Ziconius <Kris.Anderson@immersivelabs.com>"
],
"autofilter_ports": [
80,
8080,
443,
8000,
8888,
8880,
8008,
3000,
8443
],
"autofilter_services": [
"http",
"https"
],
"check": true,
"default_credential": false,
"description": "This module exploits an arbitrary command execution vulnerability in Webmin\n 1.900 and lower versions. Any user authorized to the \"Upload and Download\"\n module can execute arbitrary commands with root privileges.\n\n In addition, if the 'Running Processes' (proc) privilege is set the user can\n accurately determine which directory to upload to. Webmin application files\n can be written/overwritten, which allows remote code execution. The module\n has been tested successfully with Webmin 1.900 on Ubuntu v18.04.\n\n Using GUESSUPLOAD attempts to use a default installation path in order to\n trigger the exploit.",
"disclosure_date": "2019-01-17",
"fullname": "exploit/unix/webapp/webmin_upload_exec",
"is_install_path": true,
"mod_time": "2026-04-22 11:59:12 +0000",
"name": "Webmin Upload Authenticated RCE",
"needs_cleanup": true,
"notes": {
"Reliability": [
"unknown-reliability"
],
"SideEffects": [
"unknown-side-effects"
],
"Stability": [
"unknown-stability"
]
},
"path": "/modules/exploits/unix/webapp/webmin_upload_exec.rb",
"platform": "Unix",
"post_auth": true,
"rank": 600,
"ref_name": "unix/webapp/webmin_upload_exec",
"references": [
"CVE-2019-9624",
"EDB-46201",
"URL-https://pentest.com.tr/exploits/Webmin-1900-Remote-Command-Execution.html"
],
"rport": 10000,
"session_types": false,
"targets": [
"Webmin <= 1.900"
],
"type": "exploit"
} | — |
| Rank rank | Metasploit exploit modules | 600 Excellent. Cannot crash the service. A memory-corruption exploit does not qualify. receipt
What the source handed over{
"aliases": [],
"arch": "cmd",
"author": [
"AkkuS <Özkan Mustafa Akkuş>",
"Ziconius <Kris.Anderson@immersivelabs.com>"
],
"autofilter_ports": [
80,
8080,
443,
8000,
8888,
8880,
8008,
3000,
8443
],
"autofilter_services": [
"http",
"https"
],
"check": true,
"default_credential": false,
"description": "This module exploits an arbitrary command execution vulnerability in Webmin\n 1.900 and lower versions. Any user authorized to the \"Upload and Download\"\n module can execute arbitrary commands with root privileges.\n\n In addition, if the 'Running Processes' (proc) privilege is set the user can\n accurately determine which directory to upload to. Webmin application files\n can be written/overwritten, which allows remote code execution. The module\n has been tested successfully with Webmin 1.900 on Ubuntu v18.04.\n\n Using GUESSUPLOAD attempts to use a default installation path in order to\n trigger the exploit.",
"disclosure_date": "2019-01-17",
"fullname": "exploit/unix/webapp/webmin_upload_exec",
"is_install_path": true,
"mod_time": "2026-04-22 11:59:12 +0000",
"name": "Webmin Upload Authenticated RCE",
"needs_cleanup": true,
"notes": {
"Reliability": [
"unknown-reliability"
],
"SideEffects": [
"unknown-side-effects"
],
"Stability": [
"unknown-stability"
]
},
"path": "/modules/exploits/unix/webapp/webmin_upload_exec.rb",
"platform": "Unix",
"post_auth": true,
"rank": 600,
"ref_name": "unix/webapp/webmin_upload_exec",
"references": [
"CVE-2019-9624",
"EDB-46201",
"URL-https://pentest.com.tr/exploits/Webmin-1900-Remote-Command-Execution.html"
],
"rport": 10000,
"session_types": false,
"targets": [
"Webmin <= 1.900"
],
"type": "exploit"
} | — |
| Type type | Exploit-DB | remotereceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "AkkuS",
"codes": "CVE-2019-9624",
"date_added": "2019-01-18",
"date_published": "2019-01-18",
"date_updated": "2019-03-08",
"description": "Webmin 1.900 - Remote Command Execution (Metasploit)",
"file": "exploits/cgi/remote/46201.rb",
"id": "46201",
"platform": "cgi",
"port": "10000",
"screenshot_url": "",
"source_url": "",
"tags": "Metasploit Framework (MSF)",
"type": "remote",
"verified": "0"
} | — |
| Verified verified | Exploit-DB | falsereceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "AkkuS",
"codes": "CVE-2019-9624",
"date_added": "2019-01-18",
"date_published": "2019-01-18",
"date_updated": "2019-03-08",
"description": "Webmin 1.900 - Remote Command Execution (Metasploit)",
"file": "exploits/cgi/remote/46201.rb",
"id": "46201",
"platform": "cgi",
"port": "10000",
"screenshot_url": "",
"source_url": "",
"tags": "Metasploit Framework (MSF)",
"type": "remote",
"verified": "0"
} | — |
exploit
| Webmin Upload Authenticated RCE zetlyn/cve-metasploit · 2019-01-17 | platform Unix rank 600 | source |
| Webmin 1.900 - Remote Command Execution (Metasploit) zetlyn/cve-exploitdb · 2019-01-18 | author AkkuS platform cgi type remote verified false | source |