← All CVEs

CVE-2012-2982

medium · 6.5

file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) character.

6.5
CVSS
62.2%
EPSS (exploit prob.)
99th
EPSS percentile
2012-09-11
Published

AV:N/AC:L/Au:S/C:P/I:P/A:P

Affected products

VendorProductAffected versions
gentoowebmin<= 1.590
gentoowebmin1.140
gentoowebmin1.150
gentoowebmin1.160
gentoowebmin1.170
gentoowebmin1.180
gentoowebmin1.200
gentoowebmin1.210
gentoowebmin1.220
gentoowebmin1.230
gentoowebmin1.240
gentoowebmin1.260
gentoowebmin1.270
gentoowebmin1.280
gentoowebmin1.290
gentoowebmin1.300
gentoowebmin1.310
gentoowebmin1.320
gentoowebmin1.330
gentoowebmin1.340
gentoowebmin1.370
gentoowebmin1.380
gentoowebmin1.390
gentoowebmin1.400
gentoowebmin1.410
gentoowebmin1.420
gentoowebmin1.430
gentoowebmin1.440
gentoowebmin1.450
gentoowebmin1.470
gentoowebmin1.480
gentoowebmin1.500
gentoowebmin1.510
gentoowebmin1.520
gentoowebmin1.530
gentoowebmin1.550
gentoowebmin1.560
gentoowebmin1.570
gentoowebmin1.580

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2012-2982