CVE-2012-2981

Webmin < 1.590 - Authenticated Remote Code Execution via Monitor Type Name Parameter

Title source: llm
STIX 2.1

Description

Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary Perl code via a crafted file associated with the type (aka monitor type name) parameter.

References (6)

Core 6
Core References
Various Sources x_refsource_misc
http://americaninfosec.com/research/index.html
Patch, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/788478
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1027507

Scores

EPSS 0.0078
EPSS Percentile 73.9%

Details

CWE
CWE-20
Status published
Products (39)
gentoo/webmin 1.140
gentoo/webmin 1.150
gentoo/webmin 1.160
gentoo/webmin 1.170
gentoo/webmin 1.180
gentoo/webmin 1.200
gentoo/webmin 1.210
gentoo/webmin 1.220
gentoo/webmin 1.230
gentoo/webmin 1.240
... and 29 more
Published Sep 11, 2012
Tracked Since Feb 18, 2026