CVE-2012-2983
Webmin Edit_html.cgi File Parameter Traversal Arbitrary File Access
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
file/edit_html.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file's unedited contents, which allows remote attackers to read arbitrary files via the file field.
file/edit_html.cgi en Webmin v1.590 y anteriores no realiza una comprobación de autorización antes de mostrar el contenido de un archivo sin editar, lo que permite a atacantes remotos leer archivos de su elección a través del campo de archivo.
Multiple XSS, CSRF, and arbitrary code execution vulnerabilities that impact Webmin versions prior to 1.620. SA51201. The 1.680 version fixed security issues that could be exploited by un-trusted Webmin users in the PHP Configuration and Webalizer modules. The Authen::Libwrap perl module used by Webmin is also being provided. The updated packages have been upgraded to the 1.680 version which is not vulnerable to these issues.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-05-30 CVE Reserved
- 2012-09-11 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-31 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-287: Improper Authentication
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://americaninfosec.com/research/index.html | X_refsource_misc | |
http://www.americaninfosec.com/research/dossiers/AISG-12-002.pdf | X_refsource_misc | |
http://www.securitytracker.com/id?1027507 | Vdb Entry | |
http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf | X_refsource_confirm | |
https://github.com/webmin/webmin/commit/4cd7bad70e23e4e19be8ccf7b9f245445b2b3b80 | X_refsource_confirm |
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/180804 | 2024-08-31 | |
https://packetstorm.news/files/id/189747 | 2025-03-12 |
URL | Date | SRC |
---|---|---|
http://www.kb.cert.org/vuls/id/788478 | 2013-05-30 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | <= 1.590 Search vendor "Gentoo" for product "Webmin" and version " <= 1.590" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.140 Search vendor "Gentoo" for product "Webmin" and version "1.140" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.150 Search vendor "Gentoo" for product "Webmin" and version "1.150" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.160 Search vendor "Gentoo" for product "Webmin" and version "1.160" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.170 Search vendor "Gentoo" for product "Webmin" and version "1.170" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.180 Search vendor "Gentoo" for product "Webmin" and version "1.180" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.200 Search vendor "Gentoo" for product "Webmin" and version "1.200" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.210 Search vendor "Gentoo" for product "Webmin" and version "1.210" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.220 Search vendor "Gentoo" for product "Webmin" and version "1.220" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.230 Search vendor "Gentoo" for product "Webmin" and version "1.230" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.240 Search vendor "Gentoo" for product "Webmin" and version "1.240" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.260 Search vendor "Gentoo" for product "Webmin" and version "1.260" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.270 Search vendor "Gentoo" for product "Webmin" and version "1.270" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.280 Search vendor "Gentoo" for product "Webmin" and version "1.280" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.290 Search vendor "Gentoo" for product "Webmin" and version "1.290" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.300 Search vendor "Gentoo" for product "Webmin" and version "1.300" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.310 Search vendor "Gentoo" for product "Webmin" and version "1.310" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.320 Search vendor "Gentoo" for product "Webmin" and version "1.320" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.330 Search vendor "Gentoo" for product "Webmin" and version "1.330" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.340 Search vendor "Gentoo" for product "Webmin" and version "1.340" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.370 Search vendor "Gentoo" for product "Webmin" and version "1.370" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.380 Search vendor "Gentoo" for product "Webmin" and version "1.380" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.390 Search vendor "Gentoo" for product "Webmin" and version "1.390" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.400 Search vendor "Gentoo" for product "Webmin" and version "1.400" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.410 Search vendor "Gentoo" for product "Webmin" and version "1.410" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.420 Search vendor "Gentoo" for product "Webmin" and version "1.420" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.430 Search vendor "Gentoo" for product "Webmin" and version "1.430" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.440 Search vendor "Gentoo" for product "Webmin" and version "1.440" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.450 Search vendor "Gentoo" for product "Webmin" and version "1.450" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.470 Search vendor "Gentoo" for product "Webmin" and version "1.470" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.480 Search vendor "Gentoo" for product "Webmin" and version "1.480" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.500 Search vendor "Gentoo" for product "Webmin" and version "1.500" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.510 Search vendor "Gentoo" for product "Webmin" and version "1.510" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.520 Search vendor "Gentoo" for product "Webmin" and version "1.520" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.530 Search vendor "Gentoo" for product "Webmin" and version "1.530" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.550 Search vendor "Gentoo" for product "Webmin" and version "1.550" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.560 Search vendor "Gentoo" for product "Webmin" and version "1.560" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.570 Search vendor "Gentoo" for product "Webmin" and version "1.570" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.580 Search vendor "Gentoo" for product "Webmin" and version "1.580" | - |
Affected
|