Записи DirectAdmin
15 опубликованных записей вендора directadmin.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-20 Improper Input Validation1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-598 Use of HTTP Request With Sensitive Query String1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
15 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2017-18045Эксплойта нет | JBMC DirectAdmin before 1.52, when the email_ftp_password_change setting is nonzero, allows remote attackers to obtain access or cause a dendirectadmin · directadmin | Критическая9,8 | — | 1,4 % | 21 янв. 2018 г. |
36Наблюдать | CVE-2019-9625Proof of concept | JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account.directadmin · directadmin · CWE-352 | Высокая8,8 | — | 2,4 % | 7 мар. 2019 г. |
35Наблюдать | CVE-2009-1525Эксплойта нет | CMD_DB in JBMC Software DirectAdmin before 1.334 allows remote authenticated users to gain privileges via shell metacharacters in the name pdirectadmin · directadmin · CWE-20 | Высокая8,5 | — | 2,5 % | 5 мая 2009 г. |
32Наблюдать | CVE-2025-56551Эксплойта нет | An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate login interface with adirectadmin · directadmin · CWE-598 | Высокая8,2 | — | 0,4 % | 3 окт. 2025 г. |
27Наблюдать | CVE-2007-1926Эксплойта нет | Cross-site scripting (XSS) vulnerability in JBMC Software DirectAdmin before 1.293 does not properly display log files, which allows remote directadmin · directadmin · CWE-79 | Средняя6,8 | — | 1,6 % | 10 апр. 2007 г. |
27Наблюдать | CVE-2009-1526Proof of concept | JBMC Software DirectAdmin before 1.334 allows local users to create or overwrite any file via a symlink attack on an arbitrary file in a cerdirectadmin · directadmin · CWE-59 | Средняя6,9 | — | 0,6 % | 5 мая 2009 г. |
25Наблюдать | CVE-2019-11193Proof of concept | The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESELLER; an attacker cadirectadmin · directadmin · CWE-79 | Средняя6,1 | — | 2,1 % | 30 апр. 2019 г. |
25Наблюдать | CVE-2006-5983Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in JBMC Software DirectAdmin 1.28.1 allow remote authenticated users to inject arbitrarydirectadmin · directadmin · CWE-79 | Средняя6,0 | — | 1,8 % | 20 нояб. 2006 г. |
24Наблюдать | CVE-2009-2216Proof of concept | Cross-site scripting (XSS) vulnerability in CMD_REDIRECT in DirectAdmin 1.33.6 and earlier allows remote attackers to inject arbitrary web sdirectadmin · directadmin · CWE-79 | Средняя6,1 | — | 1,5 % | 25 июн. 2009 г. |
18Наблюдать | CVE-2007-1508Proof of concept | Cross-site scripting (XSS) vulnerability in CMD_USER_STATS in DirectAdmin allows remote attackers to inject arbitrary web script or HTML viadirectadmin · directadmin · CWE-79 | Средняя4,3 | — | 1,8 % | 20 мар. 2007 г. |
17Наблюдать | CVE-2007-3501Эксплойта нет | Cross-site scripting (XSS) vulnerability in CMD_USER_STATS in DirectAdmin 1.30.1 and earlier allows remote attackers to inject arbitrary webdirectadmin · directadmin | Средняя4,3 | — | 1,2 % | 29 июн. 2007 г. |
17Наблюдать | CVE-2012-3842Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in CMD_DOMAIN in JBMC Software DirectAdmin 1.403 allow remote authenticated users with cdirectadmin · directadmin · CWE-79 | Средняя4,3 | — | 1,2 % | 3 июл. 2012 г. |
17Наблюдать | CVE-2012-5305Эксплойта нет | Cross-site scripting (XSS) vulnerability in CMD_DOMAIN in JBMC Software DirectAdmin 1.403 allows remote attackers to inject arbitrary web scdirectadmin · directadmin · CWE-79 | Средняя4,3 | — | 1,2 % | 6 окт. 2012 г. |
17Наблюдать | CVE-2007-4830Эксплойта нет | Cross-site scripting (XSS) vulnerability in CMD_BANDWIDTH_BREAKDOWN in DirectAdmin 1.30.2 and earlier allows remote attackers to inject arbidirectadmin · directadmin · CWE-79 | Средняя4,3 | — | 1,1 % | 12 сент. 2007 г. |
17Наблюдать | CVE-2011-5033Proof of concept | Stack-based buffer overflow in CFS.c in ConfigServer Security & Firewall (CSF) before 5.43, when running on a DirectAdmin server, allows locconfigserver · configserver security firewall · CWE-119 | Средняя4,4 | — | 0,7 % | 29 дек. 2011 г. |
- CVE-2017-1804539Наблюдать
JBMC DirectAdmin before 1.52, when the email_ftp_password_change setting is nonzero, allows remote attackers to obtain access or cause a den
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %directadmin · directadmin21 янв. 2018 г.
- CVE-2019-962536Наблюдать
JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account.
ВысокаяCVSS 8,8Proof of conceptEPSS 2 %directadmin · directadmin7 мар. 2019 г.
- CVE-2009-152535Наблюдать
CMD_DB in JBMC Software DirectAdmin before 1.334 allows remote authenticated users to gain privileges via shell metacharacters in the name p
ВысокаяCVSS 8,5Эксплойта нетEPSS 2 %directadmin · directadmin5 мая 2009 г.
- CVE-2025-5655132Наблюдать
An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate login interface with a
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %directadmin · directadmin3 окт. 2025 г.
- CVE-2007-192627Наблюдать
Cross-site scripting (XSS) vulnerability in JBMC Software DirectAdmin before 1.293 does not properly display log files, which allows remote
СредняяCVSS 6,8Эксплойта нетEPSS 2 %directadmin · directadmin10 апр. 2007 г.
- CVE-2009-152627Наблюдать
JBMC Software DirectAdmin before 1.334 allows local users to create or overwrite any file via a symlink attack on an arbitrary file in a cer
СредняяCVSS 6,9Proof of conceptEPSS 1 %directadmin · directadmin5 мая 2009 г.
- CVE-2019-1119325Наблюдать
The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESELLER; an attacker ca
СредняяCVSS 6,1Proof of conceptEPSS 2 %directadmin · directadmin30 апр. 2019 г.
- CVE-2006-598325Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in JBMC Software DirectAdmin 1.28.1 allow remote authenticated users to inject arbitrary
СредняяCVSS 6,0Proof of conceptEPSS 2 %directadmin · directadmin20 нояб. 2006 г.
- CVE-2009-221624Наблюдать
Cross-site scripting (XSS) vulnerability in CMD_REDIRECT in DirectAdmin 1.33.6 and earlier allows remote attackers to inject arbitrary web s
СредняяCVSS 6,1Proof of conceptEPSS 2 %directadmin · directadmin25 июн. 2009 г.
- CVE-2007-150818Наблюдать
Cross-site scripting (XSS) vulnerability in CMD_USER_STATS in DirectAdmin allows remote attackers to inject arbitrary web script or HTML via
СредняяCVSS 4,3Proof of conceptEPSS 2 %directadmin · directadmin20 мар. 2007 г.
- CVE-2007-350117Наблюдать
Cross-site scripting (XSS) vulnerability in CMD_USER_STATS in DirectAdmin 1.30.1 and earlier allows remote attackers to inject arbitrary web
СредняяCVSS 4,3Эксплойта нетEPSS 1 %directadmin · directadmin29 июн. 2007 г.
- CVE-2012-384217Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in CMD_DOMAIN in JBMC Software DirectAdmin 1.403 allow remote authenticated users with c
СредняяCVSS 4,3Эксплойта нетEPSS 1 %directadmin · directadmin3 июл. 2012 г.
- CVE-2012-530517Наблюдать
Cross-site scripting (XSS) vulnerability in CMD_DOMAIN in JBMC Software DirectAdmin 1.403 allows remote attackers to inject arbitrary web sc
СредняяCVSS 4,3Эксплойта нетEPSS 1 %directadmin · directadmin6 окт. 2012 г.
- CVE-2007-483017Наблюдать
Cross-site scripting (XSS) vulnerability in CMD_BANDWIDTH_BREAKDOWN in DirectAdmin 1.30.2 and earlier allows remote attackers to inject arbi
СредняяCVSS 4,3Эксплойта нетEPSS 1 %directadmin · directadmin12 сент. 2007 г.
- CVE-2011-503317Наблюдать
Stack-based buffer overflow in CFS.c in ConfigServer Security & Firewall (CSF) before 5.43, when running on a DirectAdmin server, allows loc
СредняяCVSS 4,4Proof of conceptEPSS 1 %configserver · configserver security firewall29 дек. 2011 г.