CVE-2012-2982 is a command injection vulnerability in file/show.cgi in Webmin 1.590 and earlier. The flaw is caused by improper neutralization of shell metacharacters in a pathname parameter; an invalid character such as the pipe (|) can be injected into the pathname and interpreted by the underlying command execution context. As a result, a remote authenticated user can cause arbitrary system commands to be executed. Available advisory context indicates the commands may run as a privileged user, and CERT/CC notes that previously established sessions can also be abused via embedded HTML, such as IMG SRC tags in HTML email, to trigger command execution on the server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a Python proof-of-concept exploit for CVE-2012-2982, targeting Webmin version 1.580. The exploit leverages an authenticated remote command execution vulnerability in the file/show.cgi component, allowing an attacker with valid credentials to execute arbitrary OS commands as root. The repository consists of a README.md with detailed usage instructions and vulnerability background, and a single exploit script (webmin.py). The script authenticates to the target Webmin instance using provided credentials, then crafts a malicious GET request to the vulnerable endpoint, injecting the user-supplied command via unsanitized input. The exploit is network-based, requires authentication, and does not hardcode payloads, instead allowing the user to specify any command. No fake or detection-only code is present; this is a functional PoC exploit.
This repository contains a single Metasploit module (Ruby file) that exploits an authenticated remote command execution vulnerability in Webmin 1.580, specifically in the /file/show.cgi component. The exploit requires valid credentials for a user with access to the File Manager module. The module first authenticates to Webmin via the /session_login.cgi endpoint, retrieves a session cookie, and then exploits the vulnerability by sending a crafted request to /file/show.cgi that injects arbitrary system commands. The payload is customizable and supports various command execution methods (generic, perl, ruby, python, telnet). If successful, the exploit provides root-level command execution on the target system. The code is weaponized, as it is part of the Metasploit framework and allows for easy payload customization. The repository is structured as a single Ruby file under the typical Metasploit module path.
This repository contains a single Python exploit script (CVE-2012-2982.py) targeting Webmin installations vulnerable to CVE-2012-2982. The exploit works by first authenticating to the target Webmin instance using provided credentials, then exploiting a command injection vulnerability in the 'file/show.cgi' endpoint to execute arbitrary shell commands. The payload is a bash reverse shell that connects back to the attacker's specified IP and port. The script requires the attacker to provide the target's address, valid credentials, and the attacker's listener details. The rest of the repository consists of IDE configuration files and .gitignore entries, with no impact on the exploit's functionality. The exploit is operational and provides a working reverse shell if the target is vulnerable and the credentials are valid.
This repository contains a Python proof-of-concept exploit for CVE-2012-2982, a remote authenticated command execution vulnerability in Webmin 1.590 and earlier. The exploit targets the /file/show.cgi endpoint, which is vulnerable to command injection via unsanitized user input. The exploit script automates authentication to Webmin, retrieves a session ID, and sends a malicious request that injects a bash reverse shell payload. The payload connects back to the attacker's machine (default port 1937, configurable) using a TCP reverse shell. The attacker must have valid Webmin credentials and set up a netcat listener to receive the shell. The repository includes a README with detailed usage instructions, prerequisites, and references. The main code file is 'cve-2012-2982-exploit.py', written in Python, and is modular for easy modification. No framework is used; this is a standalone PoC exploit.
This repository contains a Python exploit script (CVE-2012-2982.py) targeting Webmin version 1.580, specifically exploiting a remote code execution vulnerability via the /file/show.cgi endpoint (CVE-2012-2982). The exploit requires valid Webmin credentials and allows the attacker to execute a single arbitrary command on the target server. The script first logs in to Webmin using the provided credentials, then crafts a GET request to the vulnerable endpoint, injecting the command for execution. The repository is simple, containing only the exploit script and a README. The README clarifies that this is a standalone Python implementation of the exploit, not relying on Metasploit. The main entry point is CVE-2012-2982.py, which takes command-line arguments for the target, port, credentials, and command to execute. The exploit is operational and demonstrates the vulnerability effectively.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.