6.8

CVE-2012-4893

Multiple cross-site request forgery (CSRF) vulnerabilities in file/show.cgi in Webmin 1.590 and earlier allow remote attackers to hijack the authentication of privileged users for requests that (1) read files or execute (2) tar, (3) zip, or (4) gzip commands, a different issue than CVE-2012-2982.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gentoo ≫ Webmin Version <= 1.590
Gentoo ≫ Webmin Version 1.140
Gentoo ≫ Webmin Version 1.150
Gentoo ≫ Webmin Version 1.160
Gentoo ≫ Webmin Version 1.170
Gentoo ≫ Webmin Version 1.180
Gentoo ≫ Webmin Version 1.200
Gentoo ≫ Webmin Version 1.210
Gentoo ≫ Webmin Version 1.220
Gentoo ≫ Webmin Version 1.230
Gentoo ≫ Webmin Version 1.240
Gentoo ≫ Webmin Version 1.260
Gentoo ≫ Webmin Version 1.270
Gentoo ≫ Webmin Version 1.280
Gentoo ≫ Webmin Version 1.290
Gentoo ≫ Webmin Version 1.300
Gentoo ≫ Webmin Version 1.310
Gentoo ≫ Webmin Version 1.320
Gentoo ≫ Webmin Version 1.330
Gentoo ≫ Webmin Version 1.340
Gentoo ≫ Webmin Version 1.370
Gentoo ≫ Webmin Version 1.380
Gentoo ≫ Webmin Version 1.390
Gentoo ≫ Webmin Version 1.400
Gentoo ≫ Webmin Version 1.410
Gentoo ≫ Webmin Version 1.420
Gentoo ≫ Webmin Version 1.430
Gentoo ≫ Webmin Version 1.440
Gentoo ≫ Webmin Version 1.450
Gentoo ≫ Webmin Version 1.470
Gentoo ≫ Webmin Version 1.480
Gentoo ≫ Webmin Version 1.500
Gentoo ≫ Webmin Version 1.510
Gentoo ≫ Webmin Version 1.520
Gentoo ≫ Webmin Version 1.530
Gentoo ≫ Webmin Version 1.550
Gentoo ≫ Webmin Version 1.560
Gentoo ≫ Webmin Version 1.570
Gentoo ≫ Webmin Version 1.580
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.85% 0.532
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

http://americaninfosec.com/research/index.html
http://www.kb.cert.org/vuls/id/788478
US Government Resource
http://www.americaninfosec.com/research/dossiers/AISG-12-001.pdf