Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ispconfig HIGH 7.2
CVE-2023-46818EPSS 14%

An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_lange…

Fix: 3.2.11+
Fix from $1,950 2023-10-27
Ispconfig CRITICAL 9.8
CVE-2021-3021

ISPConfig before 3.2.2 allows SQL injection.

Fix: 3.2.2+
Fix from $2,300 2021-01-05
Ispconfig CRITICAL 9.8
CVE-2020-9398

ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQL Injection.

Fix: 3.1.15+
Fix from $2,300 2020-02-25
Ispconfig HIGH 8.8
CVE-2013-3629EPSS 43%

ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution

No fix yet
Fix from $1,950 2020-02-07
Ispconfig CRITICAL 9.8
CVE-2012-2087

ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface.

No fix yet
Fix from $2,300 2020-01-23
Ispconfig HIGH 7.8
CVE-2018-17984

An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code execution. This …

Fix: 3.1.13+
Fix from $1,950 2018-10-04
Ispconfig HIGH 8.8
CVE-2017-17384

ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job.

Patch available
Fix from $1,950 2017-12-07
Ispconfig MEDIUM 6.8
CVE-2015-4119

Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7 allow remote attackers to hijack the authentication of (1) a…

Fix: after 3.0.5.4
Fix from $1,600 2015-06-15
Ispconfig MEDIUM 6.5
CVE-2015-4118

SQL injection vulnerability in monitor/show_sys_state.php in ISPConfig before 3.0.5.4p7 allows remote authenticated users with monitor permissions to…

Fix: after 3.0.5.4
Fix from $1,600 2015-06-15
Ispconfig HIGH 7.5
CVE-2006-3042

Multiple PHP remote file inclusion vulnerabilities in ISPConfig 2.2.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) go_in…

No fix yet
Fix from $1,950 2006-06-15
Ispconfig HIGH 7.5
CVE-2006-2315

PHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a…

Fix: after 2.2.2
Fix from $1,950 2006-05-12