CVE-2012-2982: Gentoo Webmin
Medium severity, CVSS 6.5. EPSS: 62.2% chance of exploitation in the next 30 days.
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) character.
Affected products
- Gentoo Webmin: up to and including 1.590; version 1.140 only; version 1.150 only; version 1.160 only; version 1.170 only; version 1.180 only; …
Published 2012-09-11. Last modified 2026-06-16.