RSS   Vulnerabilities for 'Directadmin'   RSS

2019-03-07
 
CVE-2019-9625

CWE-352
 

 
JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account.

 
2018-01-21
 
CVE-2017-18045

CWE-noinfo
 

 
JBMC DirectAdmin before 1.52, when the email_ftp_password_change setting is nonzero, allows remote attackers to obtain access or cause a denial of service (segfault) via an unspecified request.

 
2012-10-06
 
CVE-2012-5305

CWE-79
 

 
Cross-site scripting (XSS) vulnerability in CMD_DOMAIN in JBMC Software DirectAdmin 1.403 allows remote attackers to inject arbitrary web script or HTML via the domain parameter.

 
2007-09-12
 
CVE-2007-4830

CWE-79
 

 
Cross-site scripting (XSS) vulnerability in CMD_BANDWIDTH_BREAKDOWN in DirectAdmin 1.30.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the user parameter.

 
2007-06-29
 
CVE-2007-3501

 

 
Cross-site scripting (XSS) vulnerability in CMD_USER_STATS in DirectAdmin 1.30.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the domain parameter, a different vector than CVE-2007-1508.

 


Copyright 2024, cxsecurity.com

 

Back to Top