POC-CVE-2019-15107
by GYATT - Saturday November 16, 2024 at 08:35 PM
#1
Hello, Breachforums community.

I know this is old, but this is a great POC. Ive seen and used it many times to deface sites and get data. All you need to do is search Webmin 1.890 in Censry or Shodan.io, whichever you prefer, then see the port it's on; it's usually on default, then follow instructions on this GitHub script. 


Hidden Content
You must register or login to view this content.


This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Threatening forum members
Reply
#2
A command injection in the password_change.cgi , so when reseting password the HTTP parameter 'expire' wasn't filtering user inputs , so for poc they did sent an ' echo random string' and if it returned output it shows as vulnerable , for RCE , you just have to send the commands you want to execute rather than random string . Intrestingggg :kitten2:
I Love Data
I am gonna be  a criminal , Hehehe
Reply
#3
aight thank you bro i'll check it out
Reply
#4
thanks so much nigga, i will check it out
Reply
#5
lets see nyenyenye
Reply
#6
gona read and get sample vuln website
Reply
#7
(Nov 16, 2024, 08:35 PM)GYATT Wrote: Hello, Breachforums community.

I know this is old, but this is a great POC. Ive seen and used it many times to deface sites and get data. All you need to do is search Webmin 1.890 in Censry or Shodan.io, whichever you prefer, then see the port it's on; it's usually on default, then follow instructions on this GitHub script. 
thanks sharing sir

(Nov 16, 2024, 08:35 PM)GYATT Wrote: Hello, Breachforums community.

I know this is old, but this is a great POC. Ive seen and used it many times to deface sites and get data. All you need to do is search Webmin 1.890 in Censry or Shodan.io, whichever you prefer, then see the port it's on; it's usually on default, then follow instructions on this GitHub script. 
thanks sharing sir
Reply
#8
thanks for stuffs hope still work at this time
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  {SECRET} DATABASE OF EXPLOITS lulagain 437 26,644 1 hour ago
Last Post: XRDTX
  [POC] Google OAuth "MultiLogin" endpoint 0-day Farfallaiero 108 13,773 9 hours ago
Last Post: nobcoderfck
  Ban Any Discord Exploit phineasfisherman 7 466 Yesterday, 10:16 AM
Last Post: sniperx86
  Dokan Pro Unauthenticated SQL Injection POC | CVSS 10 Loki 42 3,777 Yesterday, 08:39 AM
Last Post: d39ug
  New Zer0 Day Wordpress A3g00n 81 3,409 May 05, 2026, 03:06 AM
Last Post: DirtyEra

Forum Jump:


 Users browsing this forum: 1 Guest(s)