Show filters
140 Total Results
Displaying 101-110 of 140
Sort by:
Attacker Value
Unknown

CVE-2018-18547

Disclosure Date: October 24, 2018 (last updated November 27, 2024)
Vesta Control Panel through 0.9.8-22 has XSS via the edit/web/ domain parameter, the list/backup/ backup parameter, the list/rrd/ period parameter, the list/directory/ dir_a parameter, or the filename to the list/directory/ URI.
0
Attacker Value
Unknown

CVE-2018-6618

Disclosure Date: May 11, 2018 (last updated November 26, 2024)
Easy Hosting Control Panel (EHCP) v0.37.12.b allows attackers to obtain sensitive information by leveraging cleartext password storage.
0
Attacker Value
Unknown

CVE-2018-6458

Disclosure Date: May 11, 2018 (last updated November 26, 2024)
Easy Hosting Control Panel (EHCP) v0.37.12.b allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF protection.
0
Attacker Value
Unknown

CVE-2018-6361

Disclosure Date: May 11, 2018 (last updated November 26, 2024)
Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the op parameter, as demonstrated by adding a backdoor FTP account.
0
Attacker Value
Unknown

CVE-2018-6617

Disclosure Date: May 11, 2018 (last updated November 26, 2024)
Easy Hosting Control Panel (EHCP) v0.37.12.b, when using a local MySQL server, allows attackers to change passwords of arbitrary database users by leveraging failure to ask for the current password.
0
Attacker Value
Unknown

CVE-2018-6619

Disclosure Date: May 11, 2018 (last updated November 26, 2024)
Easy Hosting Control Panel (EHCP) v0.37.12.b makes it easier for attackers to crack database passwords by leveraging use of a weak hashing algorithm without a salt.
0
Attacker Value
Unknown

CVE-2018-6362

Disclosure Date: May 11, 2018 (last updated November 26, 2024)
Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the domainop action parameter, as demonstrated by reading the PHPSESSID cookie.
0
Attacker Value
Unknown

CVE-2018-10686

Disclosure Date: May 06, 2018 (last updated November 08, 2023)
An issue was discovered in Vesta Control Panel 0.9.8-20. There is Reflected XSS via $_REQUEST['path'] to the view/file/index.php URI, which can lead to remote PHP code execution via vectors involving a file_put_contents call in web/upload/UploadHandler.php.
0
Attacker Value
Unknown

CVE-2015-4117

Disclosure Date: February 28, 2018 (last updated November 26, 2024)
Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter to list/backup/index.php.
0
Attacker Value
Unknown

CVE-2014-8362

Disclosure Date: January 23, 2017 (last updated November 25, 2024)
Vivint Sky Control Panel 1.1.1.9926 allows remote attackers to enable and disable the alarm system and modify other security settings via the Web-enabled interface.
0