İçeriğe atla
Noroxi

ISPConfig kayıtları

ispconfig üreticisine ait 12 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
2 · %16,7
Pre-auth RCE
2
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

12 kayıt
  • CVE-2013-3629
    48Planlayın

    ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution

    YüksekCVSS 8,8SilahlaştırılmışEPSS %43

    ispconfig · ispconfig7 Şub 2020

  • CVE-2012-2087
    40Planlayın

    ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface.

    KritikCVSS 9,8İstismar yokEPSS %3

    ispconfig · ispconfig23 Oca 2020

  • CVE-2021-3021
    40Planlayın

    ISPConfig before 3.2.2 allows SQL injection.

    KritikCVSS 9,8İstismar yokEPSS %2

    ispconfig · ispconfig5 Oca 2021

  • CVE-2020-9398
    39İzleyin

    ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQL Injection.

    KritikCVSS 9,8İstismar yokEPSS %1

    ispconfig · ispconfig25 Şub 2020

  • CVE-2017-17384
    35İzleyin

    ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job.

    YüksekCVSS 8,8İstismar yokEPSS %1

    ispconfig · ispconfig7 Ara 2017

  • CVE-2023-46818
    33İzleyin

    An issue was discovered in ISPConfig before 3.2.11p1.

    YüksekCVSS 7,2SilahlaştırılmışEPSS %16

    ispconfig · ispconfig27 Eki 2023

  • CVE-2018-17984
    32İzleyin

    An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code executi

    YüksekCVSS 7,8İstismar yokEPSS %3

    ispconfig · ispconfig4 Eki 2018

  • CVE-2006-2315
    31İzleyin

    PHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote attackers to execute arbitrary PHP c

    YüksekCVSS 7,5Kavram kanıtıEPSS %5

    ispconfig · ispconfig11 May 2006

  • CVE-2006-3042
    31İzleyin

    Multiple PHP remote file inclusion vulnerabilities in ISPConfig 2.2.3 allow remote attackers to execute arbitrary PHP code via a URL in the

    YüksekCVSS 7,5Kavram kanıtıEPSS %3

    ispconfig · ispconfig15 Haz 2006

  • CVE-2015-4118
    27İzleyin

    SQL injection vulnerability in monitor/show_sys_state.php in ISPConfig before 3.0.5.4p7 allows remote authenticated users with monitor permi

    OrtaCVSS 6,5Kavram kanıtıEPSS %2

    ispconfig · ispconfig15 Haz 2015

  • CVE-2015-4119
    27İzleyin

    Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7 allow remote attackers to hijack the authentication

    OrtaCVSS 6,8Kavram kanıtıEPSS %1

    ispconfig · ispconfig15 Haz 2015

  • CVE-2025-52206
    18İzleyin

    ISPConfig 3.3.0 is vulnerable to Cross Site Scripting (XSS) via the system status webpage.

    OrtaCVSS 4,7İstismar yokEPSS %0

    ispconfig · ispconfig5 May 2026