Lucene search

K
cve[email protected]CVE-2012-3513
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2012-3513

2022-10-0316:15:22
CWE-264
web.nvd.nist.gov
28
cve-2012-3513
munin
cgi
apache
remote attackers
files creation
security vulnerability

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

6.6 Medium

AI Score

Confidence

Low

0.013 Low

EPSS

Percentile

85.9%

munin-cgi-graph in Munin before 2.0.6, when running as a CGI module under Apache, allows remote attackers to load new configurations and create files in arbitrary directories via the logdir command.

Affected configurations

NVD
Node
munin-monitoringmuninRange2.0.5
OR
munin-monitoringmuninMatch2.0-beta1
OR
munin-monitoringmuninMatch2.0-beta2
OR
munin-monitoringmuninMatch2.0-beta3
OR
munin-monitoringmuninMatch2.0-beta4
OR
munin-monitoringmuninMatch2.0-beta5
OR
munin-monitoringmuninMatch2.0-beta6
OR
munin-monitoringmuninMatch2.0-beta7
OR
munin-monitoringmuninMatch2.0-rc1
OR
munin-monitoringmuninMatch2.0-rc2
OR
munin-monitoringmuninMatch2.0-rc3
OR
munin-monitoringmuninMatch2.0-rc4
OR
munin-monitoringmuninMatch2.0-rc5
OR
munin-monitoringmuninMatch2.0-rc6
OR
munin-monitoringmuninMatch2.0-rc7
OR
munin-monitoringmuninMatch2.0.0
OR
munin-monitoringmuninMatch2.0.1
OR
munin-monitoringmuninMatch2.0.2
OR
munin-monitoringmuninMatch2.0.3
OR
munin-monitoringmuninMatch2.0.4

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

6.6 Medium

AI Score

Confidence

Low

0.013 Low

EPSS

Percentile

85.9%