← Back

CVE-2012-4893

nvd nist
Published: Sep 11, 2012Modified: Apr 29, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in file/show.cgi in Webmin 1.590 and earlier allow remote attackers to hijack the authentication of privileged users for requests that (1) read files or execute (2) tar, (3) zip, or (4) gzip commands, a different issue than CVE-2012-2982.

Affected (39)

Products: Gentoo: Webmin
1 product
Webmin
Configuration A
39 vulnerable
Vulnerable SoftwareAffected Versions
Gentoo
Up to 1.590
Version 1.140
Version 1.150
Version 1.160
Version 1.170
Version 1.180
Version 1.200
Version 1.210
Version 1.220
Version 1.230
Version 1.240
Version 1.260
Version 1.270
Version 1.280
Version 1.290
Version 1.300
Version 1.310
Version 1.320
Version 1.330
Version 1.340
Version 1.370
Version 1.380
Version 1.390
Version 1.400
Version 1.410
Version 1.420
Version 1.430
Version 1.440
Version 1.450
Version 1.470
Version 1.480
Version 1.500
Version 1.510
Version 1.520
Version 1.530
Version 1.550
Version 1.560
Version 1.570
Version 1.580

References (6)

Source: cve@mitre.org
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource

Timeline

No history available yet.