Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2019-12792
A command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.087
EPSS Ranking
92.0%
CVSS Severity
CVSS v3 Score
8.8
CVSS v2 Score
9.0
References
https://cardaci.xyz/advisories/2019/08/12/vesta-control-panel-0.9.8-24-privilege-escalation-in-the-upload-handler/
https://github.com/serghey-rodin/vesta/issues/1921
https://cardaci.xyz/advisories/2019/08/12/vesta-control-panel-0.9.8-24-privilege-escalation-in-the-upload-handler/
https://github.com/serghey-rodin/vesta/issues/1921
Products affected by CVE-2019-12792
Vestacp
»
Control Panel
»
Version:
0.9.8-24
cpe:2.3:a:vestacp:control_panel:0.9.8-24
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved