References https://vuldb.com/vuln/136530 https://www.exploit-db.com/exploits/46984 https://www.sentinelone.com/vulnerability-database/cve-2020-35606/ https://nvd.nist.gov/vuln/detail/cve-2019-12840 https://www.broadcom.com/support/security-center/attacksignatures/detail?asid=31756 https://avd.aliyun.com/detail?id=AVD-2019-12840 https://www.tenablecloud.cn/plugins/nessus/146488 https://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/linux/http/webmin_package_updates_rce.rb https://www.secrss.com/articles/13086 https://juejin.cn/post/7166246223614214151
Related VulnerabilitiesPoCnuget-config-exposure: NuGet.config Package Source Credentials - Exposure大华-智慧园区综合管理平台 updateAccessChannelByVisit SQL注入漏洞PoCpackage-json: NPM package.json DisclosurePoCCVE-2025-13342: DynamiApps Frontend Admin <= 3.28.20 - Unauthenticated Arbitrary Options Update金和OA /c6/JHSoft.Web.CostControl/BudgetExecution/VouchUpdate.aspx SQL 注入漏洞时空智友ERP系统 /formservice updater.uploadStudioFile 文件上传漏洞PoCCVE-2025-12841: WordPress Bookit < 2.5.1 - Unauthenticated Stripe Settings UpdateUniFi OS Server latest_package 命令执行漏洞(CVE-2026-34908/CVE-2026-34909/CVE-2026-34910)NocoBase /api/sqlCollection:update SQL 注入漏洞(CVE-2026-41641)宏景 ehr /services/HrpService updateHolidays XML 外部实体注入漏洞PoC深信服运维安全管理系统 /fort/csspost;help/update 命令执行漏洞PoC深信服运维安全管理系统 /fort/timeSet;help/update_date 代码执行漏洞深科特LEAN MES PrintUpdate.aspx存在任意文件读取漏洞