Back to Database
Status published
Medium
CVE-2012-2982
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users...
Vulnerability Description
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) character.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-2982
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.americaninfosec.com/research/dossiers/AISG-12-001.pdf
- http://www.kb.cert.org/vuls/id/788478
- https://github.com/webmin/webmin/commit/1f1411fe7404ec3ac03e803cfa7e01515e71a213
- http://www.securitytracker.com/id?1027507
- http://americaninfosec.com/research/index.html
- http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf
More from gentoo
View All →CVE-2023-28424
Soko SQL Injection vulnerability
Critical
9.1
CVE-2023-26033
Gentoo soko contains DoS attack based on SQL Injection
High
7.5
CVE-2020-36770
pkg_postinst in the Gentoo ebuild for Slurm through 22.05.3 unnecessarily...
Unknown
0
CVE-2019-20384
Gentoo Portage through 2.3.84 allows local users to place a...
Medium
5.5
CVE-2017-14484
The Gentoo sci-mathematics/gimps package before 28.10-r1 for Great Internet Mersenne...
High
7.3
Affected Vendor
gentoo
View all reports →Affected Software
webmin
Vulnerable Versions:
0, 1.140, 1.150, 1.160, 1.170, 1.180, 1.200, 1.210, 1.220, 1.230, 1.240, 1.260, 1.270, 1.280, 1.290, 1.300, 1.310, 1.320, 1.330, 1.340, 1.370, 1.380, 1.390, 1.400, 1.410, 1.420, 1.430, 1.440, 1.450, 1.470, 1.480, 1.500, 1.510, 1.520, 1.530, 1.550, 1.560, 1.570, 1.580
Timeline
Official Publish:
September 11th, 2012
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.