Перейти к содержимому
Noroxi

Записи ispconfig

12 опубликованных записей вендора ispconfig.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
2 · 16,7 %
Pre-auth RCE
2
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

  1. 17
  2. 18
  3. 20
  4. 21
  5. 23
  6. 26

Столбик: всего · тёмная часть: CISA KEV.

Все записи

12 записей
  • CVE-2013-3629
    48В плане

    ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 43 %

    ispconfig · ispconfig7 февр. 2020 г.

  • CVE-2012-2087
    40В плане

    ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    ispconfig · ispconfig23 янв. 2020 г.

  • CVE-2021-3021
    40В плане

    ISPConfig before 3.2.2 allows SQL injection.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    ispconfig · ispconfig5 янв. 2021 г.

  • CVE-2020-9398
    39Наблюдать

    ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQL Injection.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    ispconfig · ispconfig25 февр. 2020 г.

  • CVE-2017-17384
    35Наблюдать

    ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    ispconfig · ispconfig7 дек. 2017 г.

  • CVE-2023-46818
    33Наблюдать

    An issue was discovered in ISPConfig before 3.2.11p1.

    ВысокаяCVSS 7,2Готовый эксплойтEPSS 16 %

    ispconfig · ispconfig27 окт. 2023 г.

  • CVE-2018-17984
    32Наблюдать

    An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code executi

    ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %

    ispconfig · ispconfig4 окт. 2018 г.

  • CVE-2006-2315
    31Наблюдать

    PHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote attackers to execute arbitrary PHP c

    ВысокаяCVSS 7,5Proof of conceptEPSS 5 %

    ispconfig · ispconfig11 мая 2006 г.

  • CVE-2006-3042
    31Наблюдать

    Multiple PHP remote file inclusion vulnerabilities in ISPConfig 2.2.3 allow remote attackers to execute arbitrary PHP code via a URL in the

    ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

    ispconfig · ispconfig15 июн. 2006 г.

  • CVE-2015-4118
    27Наблюдать

    SQL injection vulnerability in monitor/show_sys_state.php in ISPConfig before 3.0.5.4p7 allows remote authenticated users with monitor permi

    СредняяCVSS 6,5Proof of conceptEPSS 2 %

    ispconfig · ispconfig15 июн. 2015 г.

  • CVE-2015-4119
    27Наблюдать

    Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7 allow remote attackers to hijack the authentication

    СредняяCVSS 6,8Proof of conceptEPSS 1 %

    ispconfig · ispconfig15 июн. 2015 г.

  • CVE-2025-52206
    18Наблюдать

    ISPConfig 3.3.0 is vulnerable to Cross Site Scripting (XSS) via the system status webpage.

    СредняяCVSS 4,7Эксплойта нетEPSS 0 %

    ispconfig · ispconfig5 мая 2026 г.