RULE(RULE ID:307097)

Rule General Information
Release Date: 2013-04-18
Rule Name: Webmin Show.cgi Command Execution Vulnerability (CVE-2012-2982)
Severity:
CVE ID:
Rule Protection Details
Description: file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) character.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Solaris, Other Unix, FreeBSD, Linux
Reference: SecurityTrackerID:1027507
Solutions
More advisories have been published on the website, please visit for more suggestions:
https://github.com/webmin/webmin/commit/1f1411fe7404ec3ac03e803cfa7e01515e71a213