CVE-2012-2982
MEDIUM 6.5EPSS 62.2%
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) character.
- CVSS v2.0
- 6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P - EPSS
- 62.18% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2012-09-11
- Updated
- 2024-08-06
Proof-of-concept exploits (24)
- webmin/webmin/commit/1f1411fe7404ec3ac03e803cfa7e01515e71a213
- 0xF331-D3AD/CVE-2012-29820★ · 2022-06-16
- 0xTas/CVE-2012-29823★ · 2022-12-15
- AlexJS6/CVE-2012-2982_Python1★ · 2021-03-19
- Ari-Weinberg/CVE-2012-29820★ · 2021-04-06
- CpyRe/CVE-2012-29820★ · 2024-03-21
- Gvmyz/CVE-2012-2982_Python1★ · 2021-03-19
- JohnHammond/CVE-2012-298242★ · 2021-09-28
- OstojaOfficial/CVE-2012-29822★ · 2020-10-25
- Shadow-Spinner/CVE-2012-2982_python0★ · 2024-06-15
- SieGer05/CVE-2012-2982-Webmin-Exploit0★ · 2025-03-05
- SincIDK/CVE-2012-2982-Exploit-Script0★ · 2025-08-03
- SlizBinksman/CVE_2012-29820★ · 2021-11-13
- alien-keric/webmin-v1.580-exploit1★ · 2024-02-23
- blu3ming/CVE-2012-29820★ · 2022-02-16
- boriitoo/CVE-2012-29820★ · 2025-09-08
- boritopalito/CVE-2012-29820★ · 2025-09-08
- cd6629/CVE-2012-2982-Python-PoC5★ · 2020-10-30
- elliotosama/CVE-2012-29820★ · 2024-08-09
- lpuv/CVE-2012-29820★ · 2025-03-14
- tera-si/PoC-scripts-in-GO0★ · 2022-10-21
- varppi/CVE-2012-29820★ · 2023-03-10
- wizardy0ga/CVE_2012-29820★ · 2021-11-13
- JRrooot/CVE-2012-2982-Webmin-RCE