CVE-2012-2982
52Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 62%
from disclosure to weapon29 days
Published on NVDSep 11
1st PoC+29d
metasploitSep 6
exploitation probability
62%top 1% of all CVEs
observed exploitation
nono source reports it
19 public exploit(s)
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) character.
Affected products
n/a · n/apublic PoCs found — 19✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/21851githubgithub.com/JohnHammond/CVE-2012-2982★ 42githubgithub.com/cd6629/CVE-2012-2982-Python-PoC★ 5githubgithub.com/0xTas/CVE-2012-2982★ 3githubgithub.com/OstojaOfficial/CVE-2012-2982★ 2githubgithub.com/JRrooot/CVE-2012-2982-Webmin-RCE★ 1githubgithub.com/Gvmyz/CVE-2012-2982_Python★ 1githubgithub.com/varppi/CVE-2012-2982★ 0githubgithub.com/blu3ming/CVE-2012-2982★ 0githubgithub.com/0xF331-D3AD/CVE-2012-2982★ 0githubgithub.com/Ari-Weinberg/CVE-2012-2982★ 0githubgithub.com/CpyRe/CVE-2012-2982★ 0githubgithub.com/Shadow-Spinner/CVE-2012-2982_python★ 0githubgithub.com/elliotosama/CVE-2012-2982★ 0githubgithub.com/SieGer05/CVE-2012-2982-Webmin-Exploit★ 0githubgithub.com/lpuv/CVE-2012-2982★ 0githubgithub.com/SincIDK/CVE-2012-2982-Exploit-Script★ 0githubgithub.com/boriitoo/CVE-2012-2982★ 0githubgithub.com/marinovharisan/Webmin-1.580---file-show.cgi-Manual-Remote-Command-Execution-Non-Metasploit-★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://americaninfosec.com/research/index.htmlhttps://github.com/webmin/webmin/commit/1f1411fe7404ec3ac03e803cfa7e01515e71a213http://www.americaninfosec.com/research/dossiers/AISG-12-001.pdfhttp://www.kb.cert.org/vuls/id/788478http://www.securitytracker.com/id?1027507http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf