This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Gentoo First view 2012-09-11
Product Webmin Last view 2012-09-11
Version 1.390 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:gentoo:webmin

Activity : Overall

Related : CVE

  Date Alert Description
6.8 2012-09-11 CVE-2012-4893

Multiple cross-site request forgery (CSRF) vulnerabilities in file/show.cgi in Webmin 1.590 and earlier allow remote attackers to hijack the authentication of privileged users for requests that (1) read files or execute (2) tar, (3) zip, or (4) gzip commands, a different issue than CVE-2012-2982.

5 2012-09-11 CVE-2012-2983

file/edit_html.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file's unedited contents, which allows remote attackers to read arbitrary files via the file field.

6.5 2012-09-11 CVE-2012-2982

file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) character.

6 2012-09-11 CVE-2012-2981

Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary Perl code via a crafted file associated with the type (aka monitor type name) parameter.

CWE : Common Weakness Enumeration

%idName
33% (1) CWE-352 Cross-Site Request Forgery (CSRF)
33% (1) CWE-287 Improper Authentication
33% (1) CWE-20 Improper Input Validation

SAINT Exploits

Description Link
Webmin show.cgi Open Function Call Command Execution More info here

Snort® IPS/IDS

Date Description
2019-10-17 Webmin show.cgi arbitrary command injection attempt
RuleID : 51538 - Type : SERVER-WEBAPP - Revision : 1
2014-01-10 Webmin show.cgi arbitrary command injection attempt
RuleID : 24628 - Type : SERVER-WEBAPP - Revision : 6

Nessus® Vulnerability Scanner

id Description
2014-03-18 Name: The remote Mandriva Linux host is missing one or more security updates.
File: mandriva_MDVSA-2014-062.nasl - Type: ACT_GATHER_INFO