Lucene search

K
cveCertccCVE-2012-2983
HistorySep 11, 2012 - 6:55 p.m.

CVE-2012-2983

2012-09-1118:55:01
CWE-287
certcc
web.nvd.nist.gov
115
cve-2012-2983
webmin
authorization check
remote attackers
arbitrary files
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.6

Confidence

Low

EPSS

0.017

Percentile

87.8%

file/edit_html.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file’s unedited contents, which allows remote attackers to read arbitrary files via the file field.

Affected configurations

Nvd
Node
gentoowebminRange1.590
OR
gentoowebminMatch1.140
OR
gentoowebminMatch1.150
OR
gentoowebminMatch1.160
OR
gentoowebminMatch1.170
OR
gentoowebminMatch1.180
OR
gentoowebminMatch1.200
OR
gentoowebminMatch1.210
OR
gentoowebminMatch1.220
OR
gentoowebminMatch1.230
OR
gentoowebminMatch1.240
OR
gentoowebminMatch1.260
OR
gentoowebminMatch1.270
OR
gentoowebminMatch1.280
OR
gentoowebminMatch1.290
OR
gentoowebminMatch1.300
OR
gentoowebminMatch1.310
OR
gentoowebminMatch1.320
OR
gentoowebminMatch1.330
OR
gentoowebminMatch1.340
OR
gentoowebminMatch1.370
OR
gentoowebminMatch1.380
OR
gentoowebminMatch1.390
OR
gentoowebminMatch1.400
OR
gentoowebminMatch1.410
OR
gentoowebminMatch1.420
OR
gentoowebminMatch1.430
OR
gentoowebminMatch1.440
OR
gentoowebminMatch1.450
OR
gentoowebminMatch1.470
OR
gentoowebminMatch1.480
OR
gentoowebminMatch1.500
OR
gentoowebminMatch1.510
OR
gentoowebminMatch1.520
OR
gentoowebminMatch1.530
OR
gentoowebminMatch1.550
OR
gentoowebminMatch1.560
OR
gentoowebminMatch1.570
OR
gentoowebminMatch1.580
VendorProductVersionCPE
gentoowebmin*cpe:2.3:a:gentoo:webmin:*:*:*:*:*:*:*:*
gentoowebmin1.140cpe:2.3:a:gentoo:webmin:1.140:*:*:*:*:*:*:*
gentoowebmin1.150cpe:2.3:a:gentoo:webmin:1.150:*:*:*:*:*:*:*
gentoowebmin1.160cpe:2.3:a:gentoo:webmin:1.160:*:*:*:*:*:*:*
gentoowebmin1.170cpe:2.3:a:gentoo:webmin:1.170:*:*:*:*:*:*:*
gentoowebmin1.180cpe:2.3:a:gentoo:webmin:1.180:*:*:*:*:*:*:*
gentoowebmin1.200cpe:2.3:a:gentoo:webmin:1.200:*:*:*:*:*:*:*
gentoowebmin1.210cpe:2.3:a:gentoo:webmin:1.210:*:*:*:*:*:*:*
gentoowebmin1.220cpe:2.3:a:gentoo:webmin:1.220:*:*:*:*:*:*:*
gentoowebmin1.230cpe:2.3:a:gentoo:webmin:1.230:*:*:*:*:*:*:*
Rows per page:
1-10 of 391

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.6

Confidence

Low

EPSS

0.017

Percentile

87.8%