Vulnerabilities
Vulnerable Software
The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESELLER; an attacker can bypass the CSRF protection with this, and take over the administration panel.
CVSS Score
6.1
EPSS Score
0.015
Published
2019-04-30
JBMC DirectAdmin before 1.52, when the email_ftp_password_change setting is nonzero, allows remote attackers to obtain access or cause a denial of service (segfault) via an unspecified request.
CVSS Score
9.8
EPSS Score
0.008
Published
2018-01-21


Contact Us

Shodan ® - All rights reserved