This module exploits an arbitrary command execution vulnerability in Webmin
1.910 and lower versions. any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data parameter to update.cgi.
## Vulnerable Application
This module has been tested with [Webmin 1.910](https://sourceforge.net/projects/webadmin/files/webmin/1.910/)
## Verification Steps
1.`use exploit/lunix/http/webmin_packageup_rce`
2.`set rhosts <rhost>`
3.`set username <username>`
4.`set password <password>`
5.`exploit`
## Scenarios
### Tested Webmin 1.910 on Debian Linux 4.19.28-2kali1 x64