// For flags

CVE-2012-2982

Webmin 1.580 - '/file/show.cgi' Remote Command Execution

Severity Score

8.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

19
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) character.

file/show.cgi en Webmin v1.590 y anteriores permite a usuarios remotos autenticados ejecutar código arbitrario a través de un carácter no válido en un nombre de ruta, como se demostró con | (pipe).

Multiple XSS, CSRF, and arbitrary code execution vulnerabilities that impact Webmin versions prior to 1.620. SA51201. The 1.680 version fixed security issues that could be exploited by un-trusted Webmin users in the PHP Configuration and Webalizer modules. The Authen::Libwrap perl module used by Webmin is also being provided. The updated packages have been upgraded to the 1.680 version which is not vulnerable to these issues.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-05-30 CVE Reserved
  • 2012-09-11 CVE Published
  • 2012-10-10 First Exploit
  • 2024-08-06 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
References (24)
URL Date SRC
http://www.kb.cert.org/vuls/id/788478 2013-05-30
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
<= 1.590
Search vendor "Gentoo" for product "Webmin" and version " <= 1.590"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.140
Search vendor "Gentoo" for product "Webmin" and version "1.140"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.150
Search vendor "Gentoo" for product "Webmin" and version "1.150"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.160
Search vendor "Gentoo" for product "Webmin" and version "1.160"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.170
Search vendor "Gentoo" for product "Webmin" and version "1.170"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.180
Search vendor "Gentoo" for product "Webmin" and version "1.180"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.200
Search vendor "Gentoo" for product "Webmin" and version "1.200"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.210
Search vendor "Gentoo" for product "Webmin" and version "1.210"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.220
Search vendor "Gentoo" for product "Webmin" and version "1.220"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.230
Search vendor "Gentoo" for product "Webmin" and version "1.230"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.240
Search vendor "Gentoo" for product "Webmin" and version "1.240"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.260
Search vendor "Gentoo" for product "Webmin" and version "1.260"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.270
Search vendor "Gentoo" for product "Webmin" and version "1.270"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.280
Search vendor "Gentoo" for product "Webmin" and version "1.280"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.290
Search vendor "Gentoo" for product "Webmin" and version "1.290"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.300
Search vendor "Gentoo" for product "Webmin" and version "1.300"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.310
Search vendor "Gentoo" for product "Webmin" and version "1.310"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.320
Search vendor "Gentoo" for product "Webmin" and version "1.320"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.330
Search vendor "Gentoo" for product "Webmin" and version "1.330"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.340
Search vendor "Gentoo" for product "Webmin" and version "1.340"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.370
Search vendor "Gentoo" for product "Webmin" and version "1.370"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.380
Search vendor "Gentoo" for product "Webmin" and version "1.380"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.390
Search vendor "Gentoo" for product "Webmin" and version "1.390"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.400
Search vendor "Gentoo" for product "Webmin" and version "1.400"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.410
Search vendor "Gentoo" for product "Webmin" and version "1.410"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.420
Search vendor "Gentoo" for product "Webmin" and version "1.420"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.430
Search vendor "Gentoo" for product "Webmin" and version "1.430"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.440
Search vendor "Gentoo" for product "Webmin" and version "1.440"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.450
Search vendor "Gentoo" for product "Webmin" and version "1.450"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.470
Search vendor "Gentoo" for product "Webmin" and version "1.470"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.480
Search vendor "Gentoo" for product "Webmin" and version "1.480"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.500
Search vendor "Gentoo" for product "Webmin" and version "1.500"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.510
Search vendor "Gentoo" for product "Webmin" and version "1.510"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.520
Search vendor "Gentoo" for product "Webmin" and version "1.520"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.530
Search vendor "Gentoo" for product "Webmin" and version "1.530"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.550
Search vendor "Gentoo" for product "Webmin" and version "1.550"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.560
Search vendor "Gentoo" for product "Webmin" and version "1.560"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.570
Search vendor "Gentoo" for product "Webmin" and version "1.570"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.580
Search vendor "Gentoo" for product "Webmin" and version "1.580"
-
Affected