Sploitus
Critical SQL Injection and VM Exploitation Threats Identified
Article Content
Two significant vulnerabilities have been reported: CVE-2024-51482 in ZoneMinder and CVE-2019-15107 in Webmin. CVE-2024-51482 affects ZoneMinder versions 1.37.0 to 1.37.64, allowing authenticated attackers to execute arbitrary SQL commands via a blind SQL injection. This vulnerability is critical for privacy, integrity, and availability, with a patch available in version 1.37.65. Meanwhile, CVE-2019-15107 allows exploitation of Webmin 1.810 on Ubuntu 18.04.1, enabling remote code execution. Attackers can gain root access through a backdoor, compromising the entire system. Both vulnerabilities pose severe risks to users, especially those running outdated software. The articles provide detailed exploitation methods and tools for both vulnerabilities.
Key Points: • CVE-2024-51482 allows SQL injection in ZoneMinder, affecting versions 1.37.0 to 1.37.64. • CVE-2019-15107 enables remote code execution in Webmin, compromising Ubuntu systems. • Patches are available for both vulnerabilities, but active exploitation is confirmed for CVE-2019-15107.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.