POC-CVE-2019-15107
by GYATT - Saturday November 16, 2024 at 08:35 PM
#1
Hello, Breachforums community.

I know this is old, but this is a great POC. Ive seen and used it many times to deface sites and get data. All you need to do is search Webmin 1.890 in Censry or Shodan.io, whichever you prefer, then see the port it's on; it's usually on default, then follow instructions on this GitHub script. 


Hidden Content
You must register or login to view this content.

This forum account is currently banned. Ban Length: (Permanent)
Ban Reason: Threatening forum members
Reply
#2
A command injection in the password_change.cgi , so when reseting password the HTTP parameter 'expire' wasn't filtering user inputs , so for poc they did sent an ' echo random string' and if it returned output it shows as vulnerable , for RCE , you just have to send the commands you want to execute rather than random string . Intrestingggg kitten2
I Love Data
[Image: Capture.png]
I am gonna be  a criminal , Hehehe
Reply
#3
aight thank you bro i'll check it out
Reply
#4
thanks so much nigga, i will check it out
Reply
#5
lets see nyenyenye
Reply
#6
gona read and get sample vuln website
Reply
#7
(11-16-2024, 08:35 PM)GYATT Wrote: Hello, Breachforums community.

I know this is old, but this is a great POC. Ive seen and used it many times to deface sites and get data. All you need to do is search Webmin 1.890 in Censry or Shodan.io, whichever you prefer, then see the port it's on; it's usually on default, then follow instructions on this GitHub script. 
thanks sharing sir

(11-16-2024, 08:35 PM)GYATT Wrote: Hello, Breachforums community.

I know this is old, but this is a great POC. Ive seen and used it many times to deface sites and get data. All you need to do is search Webmin 1.890 in Censry or Shodan.io, whichever you prefer, then see the port it's on; it's usually on default, then follow instructions on this GitHub script. 
thanks sharing sir
Reply
#8
thanks for stuffs hope still work at this time
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  POC for CVE-2019-16891 or CVE-2020-7961? darkspeed 3 569 03-15-2025, 04:10 PM
Last Post: Kayiyan
  Exploit for Arbitrary File Read on Pulse Secure SSL VPN (CVE-2019-11510) creek97 0 4,164 11-23-2023, 02:30 PM
Last Post: creek97

Forum Jump:


 Users browsing this thread: