Home / os / winmobile

Webmin 1.920 rpc.cgi Remote Root

Posted on 03 September 2019

This Metasploit module exploits Webmin versions 1.930 and below. This exploit takes advantage of a code execution issue within the function unserialise_variable() located in web-lib-funcs.pl, in order to gain root. The only prerequisite is a valid session id.

 

TOP