Skip to content
Noroxi

ISPConfig records

12 published records for vendor ispconfig.

Researcher profile

Entered KEV
0 · 0%
Weaponized
2 · 16.7%
Pre-auth RCE
2
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

12 records
  • ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution

    HighCVSS 8.8WeaponizedEPSS 43%

    ispconfig · ispconfigFeb 7, 2020

  • ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface.

    CriticalCVSS 9.8No exploitEPSS 3%

    ispconfig · ispconfigJan 23, 2020

  • ISPConfig before 3.2.2 allows SQL injection.

    CriticalCVSS 9.8No exploitEPSS 2%

    ispconfig · ispconfigJan 5, 2021

  • CVE-2020-9398
    39Monitor

    ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQL Injection.

    CriticalCVSS 9.8No exploitEPSS 1%

    ispconfig · ispconfigFeb 25, 2020

  • ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job.

    HighCVSS 8.8No exploitEPSS 1%

    ispconfig · ispconfigDec 7, 2017

  • An issue was discovered in ISPConfig before 3.2.11p1.

    HighCVSS 7.2WeaponizedEPSS 16%

    ispconfig · ispconfigOct 27, 2023

  • An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code executi

    HighCVSS 7.8No exploitEPSS 3%

    ispconfig · ispconfigOct 4, 2018

  • CVE-2006-2315
    31Monitor

    PHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote attackers to execute arbitrary PHP c

    HighCVSS 7.5Proof of conceptEPSS 5%

    ispconfig · ispconfigMay 11, 2006

  • CVE-2006-3042
    31Monitor

    Multiple PHP remote file inclusion vulnerabilities in ISPConfig 2.2.3 allow remote attackers to execute arbitrary PHP code via a URL in the

    HighCVSS 7.5Proof of conceptEPSS 3%

    ispconfig · ispconfigJun 15, 2006

  • CVE-2015-4118
    27Monitor

    SQL injection vulnerability in monitor/show_sys_state.php in ISPConfig before 3.0.5.4p7 allows remote authenticated users with monitor permi

    MediumCVSS 6.5Proof of conceptEPSS 2%

    ispconfig · ispconfigJun 15, 2015

  • CVE-2015-4119
    27Monitor

    Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7 allow remote attackers to hijack the authentication

    MediumCVSS 6.8Proof of conceptEPSS 1%

    ispconfig · ispconfigJun 15, 2015

  • ISPConfig 3.3.0 is vulnerable to Cross Site Scripting (XSS) via the system status webpage.

    MediumCVSS 4.7No exploitEPSS 0%

    ispconfig · ispconfigMay 5, 2026