Vulnerabilities
Vulnerable Software
Directadmin:  Security Vulnerabilities
JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account.
CVSS Score
8.8
EPSS Score
0.002
Published
2019-03-07
JBMC DirectAdmin before 1.52, when the email_ftp_password_change setting is nonzero, allows remote attackers to obtain access or cause a denial of service (segfault) via an unspecified request.
CVSS Score
9.8
EPSS Score
0.007
Published
2018-01-21
Cross-site scripting (XSS) vulnerability in CMD_DOMAIN in JBMC Software DirectAdmin 1.403 allows remote attackers to inject arbitrary web script or HTML via the domain parameter.
CVSS Score
4.3
EPSS Score
0.003
Published
2012-10-06
Stack-based buffer overflow in CFS.c in ConfigServer Security & Firewall (CSF) before 5.43, when running on a DirectAdmin server, allows local users to cause a denial of service (crash) via a long string in an admin.list file.
CVSS Score
4.4
EPSS Score
0.002
Published
2011-12-29
Cross-site scripting (XSS) vulnerability in CMD_BANDWIDTH_BREAKDOWN in DirectAdmin 1.30.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the user parameter.
CVSS Score
4.3
EPSS Score
0.003
Published
2007-09-12
Cross-site scripting (XSS) vulnerability in CMD_USER_STATS in DirectAdmin 1.30.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the domain parameter, a different vector than CVE-2007-1508.
CVSS Score
4.3
EPSS Score
0.005
Published
2007-06-30


Contact Us

Shodan ® - All rights reserved