Webmin Hacktricks __exclusive__ Page

Webmin is a web-based system administration tool for Unix/Linux. It runs on port 10000 (HTTPS by default) and allows managing users, services, firewalls, and more via a web GUI. Its powerful nature makes it a high-value target during internal/external pentests.

Send a crafted POST request to /password_change.cgi with the old parameter containing a pipe command | . # Payload Example old=test|id&new1=newpass&new2=newpass Use code with caution. Result: The command id is executed as root. B. Authenticated RCE via Package Updates (Metasploit) webmin hacktricks

Webmin < 1.998 Pre-requisite: Authenticated as any user. Webmin is a web-based system administration tool for

If you have root access, install a backdoored module: install a backdoored module: