// For flags

CVE-2012-2983

Webmin Edit_html.cgi File Parameter Traversal Arbitrary File Access

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

file/edit_html.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file's unedited contents, which allows remote attackers to read arbitrary files via the file field.

file/edit_html.cgi en Webmin v1.590 y anteriores no realiza una comprobación de autorización antes de mostrar el contenido de un archivo sin editar, lo que permite a atacantes remotos leer archivos de su elección a través del campo de archivo.

Multiple XSS, CSRF, and arbitrary code execution vulnerabilities that impact Webmin versions prior to 1.620. SA51201. The 1.680 version fixed security issues that could be exploited by un-trusted Webmin users in the PHP Configuration and Webalizer modules. The Authen::Libwrap perl module used by Webmin is also being provided. The updated packages have been upgraded to the 1.680 version which is not vulnerable to these issues.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-05-30 CVE Reserved
  • 2012-09-11 CVE Published
  • 2024-08-06 CVE Updated
  • 2024-08-31 First Exploit
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-287: Improper Authentication
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
<= 1.590
Search vendor "Gentoo" for product "Webmin" and version " <= 1.590"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.140
Search vendor "Gentoo" for product "Webmin" and version "1.140"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.150
Search vendor "Gentoo" for product "Webmin" and version "1.150"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.160
Search vendor "Gentoo" for product "Webmin" and version "1.160"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.170
Search vendor "Gentoo" for product "Webmin" and version "1.170"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.180
Search vendor "Gentoo" for product "Webmin" and version "1.180"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.200
Search vendor "Gentoo" for product "Webmin" and version "1.200"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.210
Search vendor "Gentoo" for product "Webmin" and version "1.210"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.220
Search vendor "Gentoo" for product "Webmin" and version "1.220"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.230
Search vendor "Gentoo" for product "Webmin" and version "1.230"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.240
Search vendor "Gentoo" for product "Webmin" and version "1.240"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.260
Search vendor "Gentoo" for product "Webmin" and version "1.260"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.270
Search vendor "Gentoo" for product "Webmin" and version "1.270"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.280
Search vendor "Gentoo" for product "Webmin" and version "1.280"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.290
Search vendor "Gentoo" for product "Webmin" and version "1.290"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.300
Search vendor "Gentoo" for product "Webmin" and version "1.300"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.310
Search vendor "Gentoo" for product "Webmin" and version "1.310"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.320
Search vendor "Gentoo" for product "Webmin" and version "1.320"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.330
Search vendor "Gentoo" for product "Webmin" and version "1.330"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.340
Search vendor "Gentoo" for product "Webmin" and version "1.340"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.370
Search vendor "Gentoo" for product "Webmin" and version "1.370"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.380
Search vendor "Gentoo" for product "Webmin" and version "1.380"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.390
Search vendor "Gentoo" for product "Webmin" and version "1.390"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.400
Search vendor "Gentoo" for product "Webmin" and version "1.400"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.410
Search vendor "Gentoo" for product "Webmin" and version "1.410"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.420
Search vendor "Gentoo" for product "Webmin" and version "1.420"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.430
Search vendor "Gentoo" for product "Webmin" and version "1.430"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.440
Search vendor "Gentoo" for product "Webmin" and version "1.440"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.450
Search vendor "Gentoo" for product "Webmin" and version "1.450"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.470
Search vendor "Gentoo" for product "Webmin" and version "1.470"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.480
Search vendor "Gentoo" for product "Webmin" and version "1.480"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.500
Search vendor "Gentoo" for product "Webmin" and version "1.500"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.510
Search vendor "Gentoo" for product "Webmin" and version "1.510"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.520
Search vendor "Gentoo" for product "Webmin" and version "1.520"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.530
Search vendor "Gentoo" for product "Webmin" and version "1.530"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.550
Search vendor "Gentoo" for product "Webmin" and version "1.550"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.560
Search vendor "Gentoo" for product "Webmin" and version "1.560"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.570
Search vendor "Gentoo" for product "Webmin" and version "1.570"
-
Affected
Gentoo
Search vendor "Gentoo"
Webmin
Search vendor "Gentoo" for product "Webmin"
1.580
Search vendor "Gentoo" for product "Webmin" and version "1.580"
-
Affected