← Vulnerability feed

Vulnerability record · CVE-2012-2104 · published 26 August 2012

CVE-2012-2104: Munin-monitoring munin improper input validation vulnerability

Munin Monitoring · Munin

cgi-bin/munin-cgi-graph in Munin 2.x writes data to a log file without sanitizing non-printable characters, which might allow user-assisted remote attackers to inject terminal emulator escape sequences and execute arbitrary commands or delete arbitrary files via a crafted HTTP request.

6.8 CVSS 2.0 Medium EPSS 5.1% · top 8.0% CWE-20 · Improper input validation
6.8CVSS 2.0 base score
5.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

cgi-bin/munin-cgi-graph in Munin 2.x writes data to a log file without sanitizing non-printable characters, which might allow user-assisted remote attackers to inject terminal emulator escape sequences and execute arbitrary commands or delete arbitrary files via a crafted HTTP request.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-2104 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2012-3513Munin-monitoring munin permissions and access controls vulnerabilitymunin-cgi-graph in Munin before 2.0.6, when running as a CGI module under Apache, allows remote attackers to load new configurations and create files…EPSS 2.4%7.2CVE-2012-3512Munin-monitoring munin permissions and access controls vulnerabilityMunin before 2.0.6 stores plugin state files that run as root in the same group-writable directory as non-root plugins, which allows local users to e…EPSS 0.59%5.5CVE-2017-6188Munin-monitoring munin improper input validation vulnerabilityMunin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET parameters allows overwriting…EPSS 0.42%5.0CVE-2013-6048Munin-monitoring munin improper input validation vulnerabilityThe get_group_tree function in lib/Munin/Master/HTMLConfig.pm in Munin before 2.0.18 allows remote nodes to cause a denial of service (infinite loop …EPSS 2.5%5.0CVE-2012-4678Munin-monitoring munin vulnerabilitymunin-cgi-graph for Munin 2.0 rc4 does not delete temporary files, which allows remote attackers to cause a denial of service (disk consumption) via …EPSS 2.2%5.0CVE-2012-2147Munin-monitoring munin vulnerabilitymunin-cgi-graph in Munin 2.0 rc4 allows remote attackers to cause a denial of service (disk or memory consumption) via many image requests with large…EPSS 1.9%4.3CVE-2013-6359Munin-monitoring munin improper input validation vulnerabilityMunin::Master::Node in Munin before 2.0.18 allows remote attackers to cause a denial of service (abort data collection for node) via a plugin that us…EPSS 1.8%1.2CVE-2012-2103Munin-monitoring munin link following vulnerabilityThe qmailscan plugin for Munin 1.4.5 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.EPSS 0.33%

Source: NIST National Vulnerability Database (record CVE-2012-2104), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.