Lucene search

K
nvd[email protected]NVD:CVE-2012-2982
HistorySep 11, 2012 - 6:55 p.m.

CVE-2012-2982

2012-09-1118:55:01
web.nvd.nist.gov
4

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.973

Percentile

99.9%

file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) character.

Affected configurations

Nvd
Node
gentoowebminRange1.590
OR
gentoowebminMatch1.140
OR
gentoowebminMatch1.150
OR
gentoowebminMatch1.160
OR
gentoowebminMatch1.170
OR
gentoowebminMatch1.180
OR
gentoowebminMatch1.200
OR
gentoowebminMatch1.210
OR
gentoowebminMatch1.220
OR
gentoowebminMatch1.230
OR
gentoowebminMatch1.240
OR
gentoowebminMatch1.260
OR
gentoowebminMatch1.270
OR
gentoowebminMatch1.280
OR
gentoowebminMatch1.290
OR
gentoowebminMatch1.300
OR
gentoowebminMatch1.310
OR
gentoowebminMatch1.320
OR
gentoowebminMatch1.330
OR
gentoowebminMatch1.340
OR
gentoowebminMatch1.370
OR
gentoowebminMatch1.380
OR
gentoowebminMatch1.390
OR
gentoowebminMatch1.400
OR
gentoowebminMatch1.410
OR
gentoowebminMatch1.420
OR
gentoowebminMatch1.430
OR
gentoowebminMatch1.440
OR
gentoowebminMatch1.450
OR
gentoowebminMatch1.470
OR
gentoowebminMatch1.480
OR
gentoowebminMatch1.500
OR
gentoowebminMatch1.510
OR
gentoowebminMatch1.520
OR
gentoowebminMatch1.530
OR
gentoowebminMatch1.550
OR
gentoowebminMatch1.560
OR
gentoowebminMatch1.570
OR
gentoowebminMatch1.580
VendorProductVersionCPE
gentoowebmin*cpe:2.3:a:gentoo:webmin:*:*:*:*:*:*:*:*
gentoowebmin1.140cpe:2.3:a:gentoo:webmin:1.140:*:*:*:*:*:*:*
gentoowebmin1.150cpe:2.3:a:gentoo:webmin:1.150:*:*:*:*:*:*:*
gentoowebmin1.160cpe:2.3:a:gentoo:webmin:1.160:*:*:*:*:*:*:*
gentoowebmin1.170cpe:2.3:a:gentoo:webmin:1.170:*:*:*:*:*:*:*
gentoowebmin1.180cpe:2.3:a:gentoo:webmin:1.180:*:*:*:*:*:*:*
gentoowebmin1.200cpe:2.3:a:gentoo:webmin:1.200:*:*:*:*:*:*:*
gentoowebmin1.210cpe:2.3:a:gentoo:webmin:1.210:*:*:*:*:*:*:*
gentoowebmin1.220cpe:2.3:a:gentoo:webmin:1.220:*:*:*:*:*:*:*
gentoowebmin1.230cpe:2.3:a:gentoo:webmin:1.230:*:*:*:*:*:*:*
Rows per page:
1-10 of 391

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.973

Percentile

99.9%