CVE-2002-2360

Webmin 0.21-0.99 - Unauthenticated Arbitrary File Read/Write and Remote Code Execution via RPC Module

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-2360. PoCs published by Noam Rathaus.

AI-analyzed exploit summary This exploit targets a privilege escalation vulnerability in Webmin's RPC module, allowing authenticated users to execute arbitrary commands as root via insufficient permission checks. It demonstrates reading/writing to /etc/passwd and /etc/shadow to create a backdoor user.

Description

The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to arbitrary files and execute arbitrary commands via remote_foreign_require and remote_foreign_call requests.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Noam Rathaus · perlremotelinux
https://www.exploit-db.com/exploits/21765

This exploit targets a privilege escalation vulnerability in Webmin's RPC module, allowing authenticated users to execute arbitrary commands as root via insufficient permission checks. It demonstrates reading/writing to /etc/passwd and /etc/shadow to create a backdoor user.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Webmin (versions before fix for CVE-2002-2360)
Auth required
Prerequisites: Valid Webmin credentials · Network access to Webmin server · RPC module enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5591
Various Sources x_refsource_misc
http://www.securiteam.com/unixfocus/5CP0R1P80G.html
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/9983.php

Scores

EPSS 0.0364
EPSS Percentile 88.1%

Details

CWE
CWE-264
Status published
Products (22)
webmin/webmin 0.21
webmin/webmin 0.22
webmin/webmin 0.31
webmin/webmin 0.41
webmin/webmin 0.42
webmin/webmin 0.51
webmin/webmin 0.76
webmin/webmin 0.77
webmin/webmin 0.78
webmin/webmin 0.79
... and 12 more
Published Dec 31, 2002
Tracked Since Feb 18, 2026