Записи ispconfig
12 опубликованных записей вендора ispconfig.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 2 · 16,7 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-185 Incorrect Regular Expression1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
12 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
48В плане | CVE-2013-3629Готовый эксплойт | ISPConfig 3.0.5.2 has Arbitrary PHP Code Executionispconfig · ispconfig | Высокая8,8 | — | 43,1 % | 7 февр. 2020 г. |
40В плане | CVE-2012-2087Эксплойта нет | ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface.ispconfig · ispconfig · CWE-732 | Критическая9,8 | — | 2,7 % | 23 янв. 2020 г. |
40В плане | CVE-2021-3021Эксплойта нет | ISPConfig before 3.2.2 allows SQL injection.ispconfig · ispconfig · CWE-89 | Критическая9,8 | — | 2,1 % | 5 янв. 2021 г. |
39Наблюдать | CVE-2020-9398Эксплойта нет | ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQL Injection.ispconfig · ispconfig · CWE-89 | Критическая9,8 | — | 1,3 % | 25 февр. 2020 г. |
35Наблюдать | CVE-2017-17384Эксплойта нет | ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job.ispconfig · ispconfig · CWE-269 | Высокая8,8 | — | 1,5 % | 7 дек. 2017 г. |
33Наблюдать | CVE-2023-46818Готовый эксплойт | An issue was discovered in ISPConfig before 3.2.11p1.ispconfig · ispconfig · CWE-94 | Высокая7,2 | — | 15,7 % | 27 окт. 2023 г. |
32Наблюдать | CVE-2018-17984Эксплойта нет | An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code executiispconfig · ispconfig · CWE-185 | Высокая7,8 | — | 3,4 % | 4 окт. 2018 г. |
31Наблюдать | CVE-2006-2315Proof of concept | PHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote attackers to execute arbitrary PHP cispconfig · ispconfig · CWE-94 | Высокая7,5 | — | 4,8 % | 11 мая 2006 г. |
31Наблюдать | CVE-2006-3042Proof of concept | Multiple PHP remote file inclusion vulnerabilities in ISPConfig 2.2.3 allow remote attackers to execute arbitrary PHP code via a URL in the ispconfig · ispconfig | Высокая7,5 | — | 2,9 % | 15 июн. 2006 г. |
27Наблюдать | CVE-2015-4118Proof of concept | SQL injection vulnerability in monitor/show_sys_state.php in ISPConfig before 3.0.5.4p7 allows remote authenticated users with monitor permiispconfig · ispconfig · CWE-89 | Средняя6,5 | — | 2,1 % | 15 июн. 2015 г. |
27Наблюдать | CVE-2015-4119Proof of concept | Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7 allow remote attackers to hijack the authenticationispconfig · ispconfig · CWE-352 | Средняя6,8 | — | 1,3 % | 15 июн. 2015 г. |
18Наблюдать | CVE-2025-52206Эксплойта нет | ISPConfig 3.3.0 is vulnerable to Cross Site Scripting (XSS) via the system status webpage.ispconfig · ispconfig · CWE-79 | Средняя4,7 | — | 0,2 % | 5 мая 2026 г. |
- CVE-2013-362948В плане
ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution
ВысокаяCVSS 8,8Готовый эксплойтEPSS 43 %ispconfig · ispconfig7 февр. 2020 г.
- CVE-2012-208740В плане
ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %ispconfig · ispconfig23 янв. 2020 г.
- CVE-2021-302140В плане
ISPConfig before 3.2.2 allows SQL injection.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %ispconfig · ispconfig5 янв. 2021 г.
- CVE-2020-939839Наблюдать
ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQL Injection.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ispconfig · ispconfig25 февр. 2020 г.
- CVE-2017-1738435Наблюдать
ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %ispconfig · ispconfig7 дек. 2017 г.
- CVE-2023-4681833Наблюдать
An issue was discovered in ISPConfig before 3.2.11p1.
ВысокаяCVSS 7,2Готовый эксплойтEPSS 16 %ispconfig · ispconfig27 окт. 2023 г.
- CVE-2018-1798432Наблюдать
An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code executi
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %ispconfig · ispconfig4 окт. 2018 г.
- CVE-2006-231531Наблюдать
PHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote attackers to execute arbitrary PHP c
ВысокаяCVSS 7,5Proof of conceptEPSS 5 %ispconfig · ispconfig11 мая 2006 г.
- CVE-2006-304231Наблюдать
Multiple PHP remote file inclusion vulnerabilities in ISPConfig 2.2.3 allow remote attackers to execute arbitrary PHP code via a URL in the
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %ispconfig · ispconfig15 июн. 2006 г.
- CVE-2015-411827Наблюдать
SQL injection vulnerability in monitor/show_sys_state.php in ISPConfig before 3.0.5.4p7 allows remote authenticated users with monitor permi
СредняяCVSS 6,5Proof of conceptEPSS 2 %ispconfig · ispconfig15 июн. 2015 г.
- CVE-2015-411927Наблюдать
Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7 allow remote attackers to hijack the authentication
СредняяCVSS 6,8Proof of conceptEPSS 1 %ispconfig · ispconfig15 июн. 2015 г.
- CVE-2025-5220618Наблюдать
ISPConfig 3.3.0 is vulnerable to Cross Site Scripting (XSS) via the system status webpage.
СредняяCVSS 4,7Эксплойта нетEPSS 0 %ispconfig · ispconfig5 мая 2026 г.