Input validation error in Webmin - CVE-2012-2982
Published: September 11, 2012 / Updated: February 13, 2024
Vulnerability identifier: #VU43567
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-2982
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote #AU# to read and manipulate data.
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) character.
Affected software
Webmin
How to mitigate CVE-2012-2982
Install update from vendor's website.
Links to Public Exploits and PoC-codes
- Exploit #9549 - CVE-2012-2982 (my own script in python to exploit vulnerable (It based on TryHackMe Intro PoC Scripting room) ) (February 13, 2024)
- Exploit #8673 - CVE-2012-2982 (An exploit for CVE-2012-2982 implemented in Rust) (December 15, 2022)
- Exploit #6699 - CVE-2012-2982 (A Python replicated exploit for Webmin 1.580 /file/show.cgi Remote Code Execution) (September 5, 2021)
- Exploit #6603 - poc (A place where i store my proof of concepts of cve's and exploits :)) (August 8, 2021)
- Exploit #5278 - CVE-2012-2982 (Exploit for CVE-2012-2982) (April 6, 2021)
- Exploit #4762 - CVE-2012-2982 (Python exploit for CVE-2012-2982) (October 28, 2020)
- Exploit #4351 - Webmin 1.580 - /file/show.cgi Remote Command Execution (Metasploit) (August 11, 2020)
- Exploit #4099 - Webmin /file/show.cgi Remote Command Execution (August 11, 2020)
External References
- http://americaninfosec.com/research/index.html
- http://www.americaninfosec.com/research/dossiers/AISG-12-001.pdf
- http://www.kb.cert.org/vuls/id/788478
- http://www.securitytracker.com/id?1027507
- http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf
- https://github.com/webmin/webmin/commit/1f1411fe7404ec3ac03e803cfa7e01515e71a213