------------------------
Product: Webmin
------------------------
Affected version: Webmin 1.840 and possibly
earlier
------------------------
Patched version: Webmin 1.850
------------------------
Credit: Andy Tan
------------------------
CVE ID: CVE-2017-9313
------------------------
===============
Proof of Concept
================
Vulnerable Modules:
https://192.168.1.20:10000/
https://192.168.1.20:10000/
https://192.168.1.20:10000/
(Vulnerable 'name' parameter)
Vendor contact timeline:
------------------------
2017-06-12: Contacted vendor.
2017-06-28: Vendor released new patch.
2017-07-02: Public disclosure.
Komentarų nėra:
Rašyti komentarą