CVE-2012-2982

UnknownEPSS 61.92%

Last modified

CVE-2012-2982 is a vulnerability of currently unknown severity. file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) character.. EPSS estimates a 61.92% chance of exploitation in the next 30 days.

Description

file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) character.

Metrics

EPSS Probability
61.92%

99.1th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
GentooWebmin<= 1.590
GentooWebmin1.140
GentooWebmin1.150
GentooWebmin1.160
GentooWebmin1.170
GentooWebmin1.180
GentooWebmin1.200
GentooWebmin1.210
GentooWebmin1.220
GentooWebmin1.230
GentooWebmin1.240
GentooWebmin1.260
GentooWebmin1.270
GentooWebmin1.280
GentooWebmin1.290
GentooWebmin1.300
GentooWebmin1.310
GentooWebmin1.320
GentooWebmin1.330
GentooWebmin1.340
GentooWebmin1.370
GentooWebmin1.380
GentooWebmin1.390
GentooWebmin1.400
GentooWebmin1.410
GentooWebmin1.420
GentooWebmin1.430
GentooWebmin1.440
GentooWebmin1.450
GentooWebmin1.470
GentooWebmin1.480
GentooWebmin1.500
GentooWebmin1.510
GentooWebmin1.520
GentooWebmin1.530
GentooWebmin1.550
GentooWebmin1.560
GentooWebmin1.570
GentooWebmin1.580

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2012-2982?
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) character.
How severe is CVE-2012-2982?
Severity scoring for CVE-2012-2982 is pending analysis. The EPSS model estimates a 61.92% probability of exploitation in the next 30 days.
How do I fix CVE-2012-2982?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2012-2982?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST