Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2013-2097

Disclosure Date: February 12, 2020 (last updated November 28, 2024)
ZPanel through 10.1.0 has Remote Command Execution
Attacker Value
Unknown

CVE-2012-5686

Disclosure Date: February 04, 2020 (last updated February 21, 2025)
ZPanel 10.0.1 has insufficient entropy for its password reset process.
Attacker Value
Unknown

CVE-2012-5684

Disclosure Date: August 14, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in ZPanel 10.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the inFullname parameter in an UpdateAccountSettings action in the my_account module to zpanel/.
0
Attacker Value
Unknown

CVE-2012-5683

Disclosure Date: August 14, 2014 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in ZPanel 10.0.1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) create new FTP users via a CreateFTP action in the ftp_management module to the default URI, (2) conduct cross-site scripting (XSS) attacks via the inFullname parameter in an UpdateAccountSettings action in the my_account module to zpanel/, or (3) conduct SQL injection attacks via the inEmailAddress parameter in an UpdateClient action in the manage_clients module to the default URI.
0
Attacker Value
Unknown

CVE-2012-5685

Disclosure Date: August 14, 2014 (last updated October 05, 2023)
SQL injection vulnerability in ZPanel 10.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the inEmailAddress parameter in an UpdateClient action in the manage_clients module to the default URI.
0
Attacker Value
Unknown

CVE-2012-6654

Disclosure Date: August 14, 2014 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in ZPanel 10.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) resetkey or (2) inConfEmail parameter to index.php, a different vulnerability than CVE-2012-5685.
0
Attacker Value
Unknown

CVE-2007-1123

Disclosure Date: February 27, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in ZPanel 2.0 allow remote attackers to execute arbitrary PHP code via a URL in (1) the body parameter to templates/ZPanelV2/template.php or (2) the page parameter to zpanel.php. NOTE: the zpanel.php vector may overlap CVE-2005-0793.2. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2005-0794

Disclosure Date: March 15, 2005 (last updated February 22, 2025)
ZPanel 2.0 and 2.5 beta 10 does not remove or protect installation scripts after they have been used, which allows remote attackers to reinstall the software and possibly cause a denial of service via a direct request to install.php.
0
Attacker Value
Unknown

CVE-2005-0793

Disclosure Date: March 15, 2005 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in zpanel.php in ZPanel allows remote attackers to (1) execute arbitrary PHP code in ZPanel 2.0 or (2) include local files in ZPanel 2.5 beta 10 and earlier by modifying the page parameter.
0
Attacker Value
Unknown

CVE-2005-0792

Disclosure Date: March 15, 2005 (last updated February 22, 2025)
SQL injection vulnerability in ZPanel 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter to index.php or (2) page parameter to zpanel.php.
0