CVE-2023-46818
- EPSS 89.12%
- Veröffentlicht 27.10.2023 04:15:10
- Zuletzt bearbeitet 21.11.2024 08:29:22
An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_langedit is enabled.
CVE-2021-3021
- EPSS 0.44%
- Veröffentlicht 05.01.2021 16:15:15
- Zuletzt bearbeitet 21.11.2024 06:20:46
ISPConfig before 3.2.2 allows SQL injection.
CVE-2020-9398
- EPSS 0.51%
- Veröffentlicht 25.02.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 05:40:33
ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQL Injection.
CVE-2013-3629
- EPSS 77.05%
- Veröffentlicht 07.02.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 01:54:01
ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution
CVE-2012-2087
- EPSS 3.33%
- Veröffentlicht 23.01.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 01:38:27
ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface.
CVE-2018-17984
- EPSS 0.43%
- Veröffentlicht 04.10.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:19
An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code execution. This is exploitable by authenticated users who have local filesystem access.
- EPSS 0.48%
- Veröffentlicht 07.12.2017 08:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job.
CVE-2015-4119
- EPSS 4.62%
- Veröffentlicht 15.06.2015 15:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7 allow remote attackers to hijack the authentication of (1) administrators for requests that create an administrator account via a request to admin/users_edit.php...
CVE-2015-4118
- EPSS 1.91%
- Veröffentlicht 15.06.2015 15:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in monitor/show_sys_state.php in ISPConfig before 3.0.5.4p7 allows remote authenticated users with monitor permissions to execute arbitrary SQL commands via the server parameter. NOTE: this can be leveraged by remote atta...
CVE-2006-3042
- EPSS 7.2%
- Veröffentlicht 15.06.2006 10:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple PHP remote file inclusion vulnerabilities in ISPConfig 2.2.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) go_info[isp][classes_root] parameter in (a) server.inc.php, and the (2) go_info[server][classes_root] para...