Ilia Ross

3 exploits Active since Dec 2024
CVE-2026-49102 WRITEUP MEDIUM WRITEUP
Webmin < 2.640 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes component, because image/svg+xml is used instead of a safe type (e.g., text/plain).
CVSS 6.1
CVE-2026-49103 WRITEUP CRITICAL WRITEUP
Webmin < 2.640 - Path Traversal: '../filedir'
Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detachall.cgi.
CVE-2024-12828 WRITEUP HIGH WRITEUP
Webmin - Authenticated Remote Code Execution via CGI Request Handling
Webmin CGI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Webmin. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of CGI requests. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-22346.
CVSS 8.8