CVE detail
CVE-2012-2104 — CVE-2012-2104
Published 2012-08-26 · Modified 2026-06-16 · Vendor munin-monitoring · Product munin · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0508
EPSS probability
exploitation probability, 30d
92.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
cgi-bin/munin-cgi-graph in Munin 2.x writes data to a log file without sanitizing non-printable characters, which might allow user-assisted remote attackers to inject terminal emulator escape sequences and execute arbitrary commands or delete arbitrary files via a crafted HTTP request.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References