vendor:
DirectAdmin ControlPanel
by:
Amir
7,5
CVSS
HIGH
Denial of Service
N/A
CWE
Product Name: DirectAdmin ControlPanel
Affected Version From: 1.50.1
Affected Version To: All versions
Patch Exists: YES
Related CWE: N/A
CPE: a:directadmin:directadmin
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Centos 6
2018
Directadmin ControlPanel 1.50.1 denial of service Vulnerability
An attacker can send a username and password in the login screen DirectAdmin long,DirectAdmin to disrupt And Crach. This problem is present in all versions of DirectAdmin. There is no limit on the number of characters entered. attacker could write a script to attack DDoS based on the following information: http://Ip:2222/CMD_LOGIN POST /CMD_LOGIN HTTP/1.1 referer=%2F&username=$POC&password=$POC $POC = A * 10000
Mitigation:
Upgrade to the latest version of DirectAdmin