Vulnerabilities (CVE)

Filtered by vendor Ispconfig Subscribe
Filtered by product Ispconfig
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-3021 1 Ispconfig 1 Ispconfig 2021-01-07 7.5 HIGH 9.8 CRITICAL
ISPConfig before 3.2.2 allows SQL injection.
CVE-2020-9398 1 Ispconfig 1 Ispconfig 2020-03-03 9.3 HIGH 9.8 CRITICAL
ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQL Injection.
CVE-2012-2087 1 Ispconfig 1 Ispconfig 2020-01-30 7.5 HIGH 9.8 CRITICAL
ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface.