CVE-2025-56551
- EPSS 0.05%
- Veröffentlicht 03.10.2025 00:00:00
- Zuletzt bearbeitet 15.10.2025 18:34:22
An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate login interface with arbitrary attacker-controlled content via supplying a crafted GET request.
CVE-2019-11193
- EPSS 1.47%
- Veröffentlicht 30.04.2019 19:29:03
- Zuletzt bearbeitet 16.12.2025 21:13:40
The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESELLER; an attacker can bypass the CSRF protection with this, and take over the administration panel.
CVE-2019-9625
- EPSS 0.25%
- Veröffentlicht 07.03.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:51:59
JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account.
CVE-2017-18045
- EPSS 0.82%
- Veröffentlicht 21.01.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:14
JBMC DirectAdmin before 1.52, when the email_ftp_password_change setting is nonzero, allows remote attackers to obtain access or cause a denial of service (segfault) via an unspecified request.
CVE-2012-5305
- EPSS 0.29%
- Veröffentlicht 06.10.2012 22:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in CMD_DOMAIN in JBMC Software DirectAdmin 1.403 allows remote attackers to inject arbitrary web script or HTML via the domain parameter.
CVE-2012-3842
- EPSS 0.24%
- Veröffentlicht 03.07.2012 22:55:03
- Zuletzt bearbeitet 05.12.2025 20:11:23
Multiple cross-site scripting (XSS) vulnerabilities in CMD_DOMAIN in JBMC Software DirectAdmin 1.403 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via the (1) select0 or (2) select8 parameters.
CVE-2009-2216
- EPSS 2.78%
- Veröffentlicht 25.06.2009 23:14:15
- Zuletzt bearbeitet 16.12.2025 21:08:04
Cross-site scripting (XSS) vulnerability in CMD_REDIRECT in DirectAdmin 1.33.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the URI in a view=advanced request.
CVE-2009-1525
- EPSS 1.01%
- Veröffentlicht 05.05.2009 20:30:00
- Zuletzt bearbeitet 16.12.2025 21:04:43
CMD_DB in JBMC Software DirectAdmin before 1.334 allows remote authenticated users to gain privileges via shell metacharacters in the name parameter during a restore action.
CVE-2009-1526
- EPSS 0.34%
- Veröffentlicht 05.05.2009 20:30:00
- Zuletzt bearbeitet 16.12.2025 21:05:20
JBMC Software DirectAdmin before 1.334 allows local users to create or overwrite any file via a symlink attack on an arbitrary file in a certain temporary directory, related to a request for this temporary file in the PATH_INFO to the CMD_DB script d...
CVE-2007-4830
- EPSS 0.31%
- Veröffentlicht 12.09.2007 19:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in CMD_BANDWIDTH_BREAKDOWN in DirectAdmin 1.30.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the user parameter.