peter bassill · operator
$ cve CVE-2002-2360 JSON

CVE-2002-2360 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 3.6% (pctl 89)

Patch early

A public exploit exists.

Description

The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to arbitrary files and execute arbitrary commands via remote_foreign_require and remote_foreign_call requests.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS3.64% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2002-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
webminwebmin

Public exploits

SourceTitleDate
exploit-dbWebmin 0.x - 'RPC' Privilege Escalation2002-08-28

References

→ the Explorer  ·  watch your stack  ·  NVD