CVE-2012-3513

munin-cgi-graph in Munin before 2.0.6, when running as a CGI module under Apache, allows remote attackers to load new configurations and create files in arbitrary directories via the logdir command.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:munin-monitoring:munin:2.0-beta7:*:*:*:*:*:*:*
cpe:2.3:a:munin-monitoring:munin:2.0-beta6:*:*:*:*:*:*:*
cpe:2.3:a:munin-monitoring:munin:2.0-beta5:*:*:*:*:*:*:*
cpe:2.3:a:munin-monitoring:munin:2.0-beta4:*:*:*:*:*:*:*
cpe:2.3:a:munin-monitoring:munin:2.0.4:*:*:*:*:*:*:*
cpe:2.3:a:munin-monitoring:munin:2.0-rc5:*:*:*:*:*:*:*
cpe:2.3:a:munin-monitoring:munin:2.0-rc3:*:*:*:*:*:*:*
cpe:2.3:a:munin-monitoring:munin:2.0-beta2:*:*:*:*:*:*:*
cpe:2.3:a:munin-monitoring:munin:2.0-rc2:*:*:*:*:*:*:*
cpe:2.3:a:munin-monitoring:munin:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:munin-monitoring:munin:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:munin-monitoring:munin:2.0-beta3:*:*:*:*:*:*:*
cpe:2.3:a:munin-monitoring:munin:*:*:*:*:*:*:*:*
cpe:2.3:a:munin-monitoring:munin:2.0-rc6:*:*:*:*:*:*:*
cpe:2.3:a:munin-monitoring:munin:2.0-rc1:*:*:*:*:*:*:*
cpe:2.3:a:munin-monitoring:munin:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:munin-monitoring:munin:2.0-beta1:*:*:*:*:*:*:*
cpe:2.3:a:munin-monitoring:munin:2.0-rc7:*:*:*:*:*:*:*
cpe:2.3:a:munin-monitoring:munin:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:munin-monitoring:munin:2.0-rc4:*:*:*:*:*:*:*

Information

Published : 2012-11-21 15:55

Updated : 2012-11-23 03:24


NVD link : CVE-2012-3513

Mitre link : CVE-2012-3513


JSON object : View

CWE
CWE-264

Permissions, Privileges, and Access Controls

Advertisement

dedicated server usa

Products Affected

munin-monitoring

  • munin