Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-8712

Опубликовано: 14 мар. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 5
EPSS Низкий

Описание

An issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is enabled. As a result of weak default configuration settings, limited users have full access rights to the underlying Unix system files, allowing the user to read sensitive data from the local system (using Local File Include) such as the '/etc/shadow' file via a "GET /syslog/save_log.cgi?view=1&file=/etc/shadow" request.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:webmin:webmin:1.840:*:*:*:*:*:*:*
cpe:2.3:a:webmin:webmin:1.880:*:*:*:*:*:*:*

EPSS

Процентиль: 73%
0.00788
Низкий

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.8
debian
почти 8 лет назад

An issue was discovered in Webmin 1.840 and 1.880 when the default Yes ...

CVSS3: 9.8
github
больше 3 лет назад

An issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is enabled. As a result of weak default configuration settings, limited users have full access rights to the underlying Unix system files, allowing the user to read sensitive data from the local system (using Local File Include) such as the '/etc/shadow' file via a "GET /syslog/save_log.cgi?view=1&file=/etc/shadow" request.

EPSS

Процентиль: 73%
0.00788
Низкий

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-22