First published: Tue Sep 11 2012(Updated: )
Multiple cross-site request forgery (CSRF) vulnerabilities in file/show.cgi in Webmin 1.590 and earlier allow remote attackers to hijack the authentication of privileged users for requests that (1) read files or execute (2) tar, (3) zip, or (4) gzip commands, a different issue than CVE-2012-2982.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gentoo Webmin | <=1.590 | |
Gentoo Webmin | =1.140 | |
Gentoo Webmin | =1.150 | |
Gentoo Webmin | =1.160 | |
Gentoo Webmin | =1.170 | |
Gentoo Webmin | =1.180 | |
Gentoo Webmin | =1.200 | |
Gentoo Webmin | =1.210 | |
Gentoo Webmin | =1.220 | |
Gentoo Webmin | =1.230 | |
Gentoo Webmin | =1.240 | |
Gentoo Webmin | =1.260 | |
Gentoo Webmin | =1.270 | |
Gentoo Webmin | =1.280 | |
Gentoo Webmin | =1.290 | |
Gentoo Webmin | =1.300 | |
Gentoo Webmin | =1.310 | |
Gentoo Webmin | =1.320 | |
Gentoo Webmin | =1.330 | |
Gentoo Webmin | =1.340 | |
Gentoo Webmin | =1.370 | |
Gentoo Webmin | =1.380 | |
Gentoo Webmin | =1.390 | |
Gentoo Webmin | =1.400 | |
Gentoo Webmin | =1.410 | |
Gentoo Webmin | =1.420 | |
Gentoo Webmin | =1.430 | |
Gentoo Webmin | =1.440 | |
Gentoo Webmin | =1.450 | |
Gentoo Webmin | =1.470 | |
Gentoo Webmin | =1.480 | |
Gentoo Webmin | =1.500 | |
Gentoo Webmin | =1.510 | |
Gentoo Webmin | =1.520 | |
Gentoo Webmin | =1.530 | |
Gentoo Webmin | =1.550 | |
Gentoo Webmin | =1.560 | |
Gentoo Webmin | =1.570 | |
Gentoo Webmin | =1.580 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2012-4893 is high due to its potential to allow remote attackers to hijack the authentication of privileged users.
To fix CVE-2012-4893, upgrade Webmin to version 1.591 or later, which addresses the CSRF vulnerabilities.
CVE-2012-4893 poses risks such as unauthorized actions like reading sensitive files and executing commands as a privileged user.
CVE-2012-4893 affects Webmin versions 1.590 and earlier.
CVE-2012-4893 is classified as a cross-site request forgery (CSRF) vulnerability.