vendor:
DirectAdmin Web Control Panel
by:
Ashiyane Digital Security Team
8,8
CVSS
HIGH
Cross Site Request Forgery and Cross Site Scripting
352, 79
CWE
Product Name: DirectAdmin Web Control Panel
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Elementary OS
2015
DirectAdmin Web Control Panel CSRF/XSS vulnerability
DirectAdmin is a graphical web-based web hosting control panel designed to make administration of websites easier. DirectAdmin suffers from cross site request forgery and cross site scripting vulnerabilities. Exploit 1 allows users to create new files and edit existing files, Exploit 2 allows users to create new folders, and Exploit 3 allows users to rename files.
Mitigation:
Implementing proper input validation and authentication mechanisms can help mitigate the risk of CSRF and XSS attacks.