Show filters
140 Total Results
Displaying 51-60 of 140
Sort by:
Attacker Value
Unknown

CVE-2023-0125

Disclosure Date: January 09, 2023 (last updated October 08, 2023)
A vulnerability was found in Control iD Gerencia Web 1.30. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Web Interface. The manipulation of the argument Nome leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-217717 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-3967

Disclosure Date: November 13, 2022 (last updated November 08, 2023)
A vulnerability, which was classified as critical, was found in Vesta Control Panel. Affected is an unknown function of the file func/main.sh of the component sed Handler. The manipulation leads to argument injection. An attack has to be approached locally. The name of the patch is 39561c32c12cabe563de48cc96eccb9e2c655e25. It is recommended to apply a patch to fix this issue. VDB-213546 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2021-46850

Disclosure Date: October 24, 2022 (last updated October 08, 2023)
myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and remote administrative user can execute arbitrary commands via the v_sftp_license parameter when sending HTTP POST requests to the /edit/server endpoint.
Attacker Value
Unknown

CVE-2021-30071

Disclosure Date: August 18, 2022 (last updated October 08, 2023)
A cross-site scripting (XSS) vulnerability in /admin/list_key.html of HestiaCP before v1.3.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Attacker Value
Unknown

CVE-2022-2636

Disclosure Date: August 05, 2022 (last updated October 08, 2023)
Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6.
Attacker Value
Unknown

CVE-2022-2626

Disclosure Date: August 05, 2022 (last updated October 08, 2023)
Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6.
Attacker Value
Unknown

CVE-2022-2550

Disclosure Date: July 27, 2022 (last updated October 07, 2023)
OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5.
Attacker Value
Unknown

CVE-2022-36305

Disclosure Date: July 19, 2022 (last updated October 07, 2023)
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the body function at /web/api/v1/upload/UploadHandler.php.
Attacker Value
Unknown

CVE-2022-36304

Disclosure Date: July 19, 2022 (last updated October 07, 2023)
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the generate_response function at /web/api/v1/upload/UploadHandler.php.
Attacker Value
Unknown

CVE-2022-36303

Disclosure Date: July 19, 2022 (last updated October 07, 2023)
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the handle_file_upload function at /web/api/v1/upload/UploadHandler.php.