CVE-2025-56551
- EPSS 0.33%
- Veröffentlicht 03.10.2025 00:00:00
- Zuletzt bearbeitet 15.10.2025 18:34:22
An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate login interface with arbitrary attacker-controlled content via supplying a crafted GET request.
CVE-2019-11193
- EPSS 2.09%
- Veröffentlicht 30.04.2019 19:29:03
- Zuletzt bearbeitet 16.12.2025 21:13:40
The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESELLER; an attacker can bypass the CSRF protection with this, and take over the administration panel.
CVE-2019-9625
- EPSS 2.44%
- Veröffentlicht 07.03.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:51:59
JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account.
CVE-2017-18045
- EPSS 1.42%
- Veröffentlicht 21.01.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:14
JBMC DirectAdmin before 1.52, when the email_ftp_password_change setting is nonzero, allows remote attackers to obtain access or cause a denial of service (segfault) via an unspecified request.
CVE-2012-5305
- EPSS 1.16%
- Veröffentlicht 06.10.2012 22:55:02
- Zuletzt bearbeitet 16.06.2026 23:46:37
Cross-site scripting (XSS) vulnerability in CMD_DOMAIN in JBMC Software DirectAdmin 1.403 allows remote attackers to inject arbitrary web script or HTML via the domain parameter.
CVE-2012-3842
- EPSS 1.18%
- Veröffentlicht 03.07.2012 22:55:03
- Zuletzt bearbeitet 16.06.2026 23:43:59
Multiple cross-site scripting (XSS) vulnerabilities in CMD_DOMAIN in JBMC Software DirectAdmin 1.403 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via the (1) select0 or (2) select8 parameters.
CVE-2009-2216
- EPSS 1.52%
- Veröffentlicht 25.06.2009 23:14:15
- Zuletzt bearbeitet 16.06.2026 23:09:01
Cross-site scripting (XSS) vulnerability in CMD_REDIRECT in DirectAdmin 1.33.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the URI in a view=advanced request.
CVE-2009-1525
- EPSS 2.46%
- Veröffentlicht 05.05.2009 20:30:00
- Zuletzt bearbeitet 16.06.2026 23:07:27
CMD_DB in JBMC Software DirectAdmin before 1.334 allows remote authenticated users to gain privileges via shell metacharacters in the name parameter during a restore action.
CVE-2009-1526
- EPSS 0.55%
- Veröffentlicht 05.05.2009 20:30:00
- Zuletzt bearbeitet 16.06.2026 23:07:27
JBMC Software DirectAdmin before 1.334 allows local users to create or overwrite any file via a symlink attack on an arbitrary file in a certain temporary directory, related to a request for this temporary file in the PATH_INFO to the CMD_DB script d...
CVE-2007-4830
- EPSS 1.07%
- Veröffentlicht 12.09.2007 19:17:00
- Zuletzt bearbeitet 16.06.2026 22:44:52
Cross-site scripting (XSS) vulnerability in CMD_BANDWIDTH_BREAKDOWN in DirectAdmin 1.30.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the user parameter.