CVE-2012-4893
Mandriva Linux Security Advisory 2014-062
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple cross-site request forgery (CSRF) vulnerabilities in file/show.cgi in Webmin 1.590 and earlier allow remote attackers to hijack the authentication of privileged users for requests that (1) read files or execute (2) tar, (3) zip, or (4) gzip commands, a different issue than CVE-2012-2982.
Múltiples vulnerabilidades de falsificación de petición en sitios cruzados (CSRF) en file/show.cgi en Webmin v1.590 y anteriores, permite a atacantes remotos secuestrar la autenticación de usaurios privilegiados para peticiones que (1) leen archivos o ejecutan comandos (2) tar, (3) zip, o (4) gzip, una cuestion diferente de CVE-2012-2982.
Multiple XSS, CSRF, and arbitrary code execution vulnerabilities that impact Webmin versions prior to 1.620. SA51201. The 1.680 version fixed security issues that could be exploited by un-trusted Webmin users in the PHP Configuration and Webalizer modules. The Authen::Libwrap perl module used by Webmin is also being provided. The updated packages have been upgraded to the 1.680 version which is not vulnerable to these issues.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-09-11 CVE Reserved
- 2012-09-11 CVE Published
- 2024-09-16 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://americaninfosec.com/research/index.html | X_refsource_misc | |
http://www.americaninfosec.com/research/dossiers/AISG-12-001.pdf | X_refsource_misc | |
http://www.kb.cert.org/vuls/id/788478 | Third Party Advisory |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | <= 1.590 Search vendor "Gentoo" for product "Webmin" and version " <= 1.590" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.140 Search vendor "Gentoo" for product "Webmin" and version "1.140" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.150 Search vendor "Gentoo" for product "Webmin" and version "1.150" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.160 Search vendor "Gentoo" for product "Webmin" and version "1.160" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.170 Search vendor "Gentoo" for product "Webmin" and version "1.170" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.180 Search vendor "Gentoo" for product "Webmin" and version "1.180" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.200 Search vendor "Gentoo" for product "Webmin" and version "1.200" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.210 Search vendor "Gentoo" for product "Webmin" and version "1.210" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.220 Search vendor "Gentoo" for product "Webmin" and version "1.220" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.230 Search vendor "Gentoo" for product "Webmin" and version "1.230" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.240 Search vendor "Gentoo" for product "Webmin" and version "1.240" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.260 Search vendor "Gentoo" for product "Webmin" and version "1.260" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.270 Search vendor "Gentoo" for product "Webmin" and version "1.270" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.280 Search vendor "Gentoo" for product "Webmin" and version "1.280" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.290 Search vendor "Gentoo" for product "Webmin" and version "1.290" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.300 Search vendor "Gentoo" for product "Webmin" and version "1.300" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.310 Search vendor "Gentoo" for product "Webmin" and version "1.310" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.320 Search vendor "Gentoo" for product "Webmin" and version "1.320" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.330 Search vendor "Gentoo" for product "Webmin" and version "1.330" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.340 Search vendor "Gentoo" for product "Webmin" and version "1.340" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.370 Search vendor "Gentoo" for product "Webmin" and version "1.370" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.380 Search vendor "Gentoo" for product "Webmin" and version "1.380" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.390 Search vendor "Gentoo" for product "Webmin" and version "1.390" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.400 Search vendor "Gentoo" for product "Webmin" and version "1.400" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.410 Search vendor "Gentoo" for product "Webmin" and version "1.410" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.420 Search vendor "Gentoo" for product "Webmin" and version "1.420" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.430 Search vendor "Gentoo" for product "Webmin" and version "1.430" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.440 Search vendor "Gentoo" for product "Webmin" and version "1.440" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.450 Search vendor "Gentoo" for product "Webmin" and version "1.450" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.470 Search vendor "Gentoo" for product "Webmin" and version "1.470" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.480 Search vendor "Gentoo" for product "Webmin" and version "1.480" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.500 Search vendor "Gentoo" for product "Webmin" and version "1.500" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.510 Search vendor "Gentoo" for product "Webmin" and version "1.510" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.520 Search vendor "Gentoo" for product "Webmin" and version "1.520" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.530 Search vendor "Gentoo" for product "Webmin" and version "1.530" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.550 Search vendor "Gentoo" for product "Webmin" and version "1.550" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.560 Search vendor "Gentoo" for product "Webmin" and version "1.560" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.570 Search vendor "Gentoo" for product "Webmin" and version "1.570" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Webmin Search vendor "Gentoo" for product "Webmin" | 1.580 Search vendor "Gentoo" for product "Webmin" and version "1.580" | - |
Affected
|