Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2009-1526
Disclosure Date: May 05, 2009 (last updated October 04, 2023)
JBMC Software DirectAdmin before 1.334 allows local users to create or overwrite any file via a symlink attack on an arbitrary file in a certain temporary directory, related to a request for this temporary file in the PATH_INFO to the CMD_DB script during a backup action.
0
Attacker Value
Unknown
CVE-2009-1525
Disclosure Date: May 05, 2009 (last updated October 04, 2023)
CMD_DB in JBMC Software DirectAdmin before 1.334 allows remote authenticated users to gain privileges via shell metacharacters in the name parameter during a restore action.
0
Attacker Value
Unknown
CVE-2007-1508
Disclosure Date: March 20, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in CMD_USER_STATS in DirectAdmin allows remote attackers to inject arbitrary web script or HTML via the RESULT parameter, a different vector than CVE-2006-5983.
0