Webmin
Vendor:
First CVE: May 2, 2005 · Active for 21 years
5
Total CVEs
More Total CVEs than 77% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 18% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Webmin over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2005
21 years ago
Most Recent CVE
Sep 11, 2012
5,065 days ago
CVE Severity & Scoring
Webmin5 CVEs
100%
All CVEs352,708 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown5 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown5 (100.0%)
User Interaction
None0 (0.0%)
Unknown5 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown5 (100.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-2982MEDIUM file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) char | Sep 11, 2012 | 6.5 | 74 | NO | YES |
CVE-2012-2983MEDIUM file/edit_html.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file's unedited contents, which allows remote attackers to read arbitrary fi | Sep 11, 2012 | 5.0 | 35 | NO | YES |
CVE-2012-4893MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in file/show.cgi in Webmin 1.590 and earlier allow remote attackers to hijack the authentication of privileged users for | Sep 11, 2012 | 6.8 | 21 | NO | NO |
CVE-2012-2981MEDIUM Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary Perl code via a crafted file associated with the type (aka monitor type name) parameter. | Sep 11, 2012 | 6.0 | 20 | NO | NO |
CVE-2005-0427MEDIUM The ebuild of Webmin before 1.170-r3 on Gentoo Linux includes the encrypted root password in the miniserv.users file when building a tbz2 of the webmin package, which allows remote | May 2, 2005 | 5.0 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
40.0% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
20.0% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Webmin
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.580 | 4 | 6.1 | 21.4% | 0 | 2 |
| 1.570 | 4 | 6.1 | 21.4% | 0 | 2 |
| 1.560 | 4 | 6.1 | 21.4% | 0 | 2 |
| 1.550 | 4 | 6.1 | 21.4% | 0 | 2 |
| 1.530 | 4 | 6.1 | 21.4% | 0 | 2 |
| 1.520 | 4 | 6.1 | 21.4% | 0 | 2 |
| 1.510 | 4 | 6.1 | 21.4% | 0 | 2 |
| 1.500 | 4 | 6.1 | 21.4% | 0 | 2 |
| 1.480 | 4 | 6.1 | 21.4% | 0 | 2 |
| 1.470 | 4 | 6.1 | 21.4% | 0 | 2 |
| 1.450 | 4 | 6.1 | 21.4% | 0 | 2 |
| 1.440 | 4 | 6.1 | 21.4% | 0 | 2 |
| 1.430 | 4 | 6.1 | 21.4% | 0 | 2 |
| 1.420 | 4 | 6.1 | 21.4% | 0 | 2 |
| 1.410 | 4 | 6.1 | 21.4% | 0 | 2 |
| 1.400 | 4 | 6.1 | 21.4% | 0 | 2 |
| 1.390 | 4 | 6.1 | 21.4% | 0 | 2 |
| 1.380 | 4 | 6.1 | 21.4% | 0 | 2 |
| 1.370 | 4 | 6.1 | 21.4% | 0 | 2 |
| 1.340 | 4 | 6.1 | 21.4% | 0 | 2 |