CVE-2012-2982

Webmin <1.590 - Command Injection

Title source: llm

Description

file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) character.

Exploits (19)

nomisec WORKING POC 42 stars
by JohnHammond · poc
https://github.com/JohnHammond/CVE-2012-2982
nomisec WORKING POC 5 stars
by cd6629 · poc
https://github.com/cd6629/CVE-2012-2982-Python-PoC
nomisec WORKING POC 3 stars
by 0xTas · poc
https://github.com/0xTas/CVE-2012-2982
nomisec WORKING POC 2 stars
by OstojaOfficial · poc
https://github.com/OstojaOfficial/CVE-2012-2982
nomisec WORKING POC 1 stars
by Gvmyz · poc
https://github.com/Gvmyz/CVE-2012-2982_Python
nomisec WORKING POC
by lpuv · poc
https://github.com/lpuv/CVE-2012-2982
nomisec WORKING POC
by Ari-Weinberg · poc
https://github.com/Ari-Weinberg/CVE-2012-2982
nomisec STUB
by boriitoo · poc
https://github.com/boriitoo/CVE-2012-2982
nomisec WORKING POC
by 0xF331-D3AD · poc
https://github.com/0xF331-D3AD/CVE-2012-2982
nomisec WORKING POC
by blu3ming · poc
https://github.com/blu3ming/CVE-2012-2982
nomisec WORKING POC
by CpyRe · poc
https://github.com/CpyRe/CVE-2012-2982
nomisec WORKING POC
by SieGer05 · poc
https://github.com/SieGer05/CVE-2012-2982-Webmin-Exploit
nomisec WORKING POC
by elliotosama · poc
https://github.com/elliotosama/CVE-2012-2982
nomisec WORKING POC
by JRrooot · poc
https://github.com/JRrooot/CVE-2012-2982-Webmin-RCE
nomisec WORKING POC
by Shadow-Spinner · poc
https://github.com/Shadow-Spinner/CVE-2012-2982_python
nomisec WORKING POC
by SincIDK · poc
https://github.com/SincIDK/CVE-2012-2982-Exploit-Script
nomisec WORKING POC
by varppi · poc
https://github.com/varppi/CVE-2012-2982
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremoteunix
https://www.exploit-db.com/exploits/21851
metasploit WORKING POC EXCELLENT
by Unknown, juan vazquez · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/webmin_show_cgi_exec.rb

Scores

EPSS 0.8311
EPSS Percentile 99.2%

Classification

Status draft

Affected Products (39)

gentoo/webmin < 1.590
gentoo/webmin
gentoo/webmin
gentoo/webmin
gentoo/webmin
gentoo/webmin
gentoo/webmin
gentoo/webmin
gentoo/webmin
gentoo/webmin
gentoo/webmin
gentoo/webmin
gentoo/webmin
gentoo/webmin
gentoo/webmin
... and 24 more

Timeline

Published Sep 11, 2012
Tracked Since Feb 18, 2026