Vulnerabilities > Directadmin
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-03-07 | CVE-2019-9625 | Cross-Site Request Forgery (CSRF) vulnerability in Directadmin 1.55 JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account. | 6.8 |
2018-01-21 | CVE-2017-18045 | Unspecified vulnerability in Directadmin JBMC DirectAdmin before 1.52, when the email_ftp_password_change setting is nonzero, allows remote attackers to obtain access or cause a denial of service (segfault) via an unspecified request. | 7.5 |
2012-10-06 | CVE-2012-5305 | Cross-Site Scripting vulnerability in Directadmin 1.403 Cross-site scripting (XSS) vulnerability in CMD_DOMAIN in JBMC Software DirectAdmin 1.403 allows remote attackers to inject arbitrary web script or HTML via the domain parameter. | 4.3 |
2011-12-29 | CVE-2011-5033 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Configserver Security Firewall Stack-based buffer overflow in CFS.c in ConfigServer Security & Firewall (CSF) before 5.43, when running on a DirectAdmin server, allows local users to cause a denial of service (crash) via a long string in an admin.list file. | 4.4 |
2007-09-12 | CVE-2007-4830 | Cross-Site Scripting vulnerability in Directadmin Cross-site scripting (XSS) vulnerability in CMD_BANDWIDTH_BREAKDOWN in DirectAdmin 1.30.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the user parameter. | 4.3 |
2007-06-30 | CVE-2007-3501 | Cross-Site Scripting vulnerability in DirectAdmin Domain Parameter Cross-site scripting (XSS) vulnerability in CMD_USER_STATS in DirectAdmin 1.30.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the domain parameter, a different vector than CVE-2007-1508. network directadmin | 4.3 |