CVE-2002-2360 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 3.6% (pctl 89)
Patch early
A public exploit exists.
Description
The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to arbitrary files and execute arbitrary commands via remote_foreign_require and remote_foreign_call requests.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 3.64% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2002-12-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| webmin | webmin |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Webmin 0.x - 'RPC' Privilege Escalation | 2002-08-28 |
References
- http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2002-08/0403.html
- http://www.iss.net/security_center/static/9983.php
- http://www.securiteam.com/unixfocus/5CP0R1P80G.html
- http://www.securityfocus.com/bid/5591
- http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2002-08/0403.html
- http://www.iss.net/security_center/static/9983.php
- http://www.securiteam.com/unixfocus/5CP0R1P80G.html
- http://www.securityfocus.com/bid/5591
→ the Explorer · watch your stack · NVD