vendor:
DirectAdmin
by:
InfinitumIT
8.8
CVSS
HIGH
Multiple
79
CWE
Product Name: DirectAdmin
Affected Version From: Up to v1.561
Affected Version To: Up to v1.561
Patch Exists: NO
Related CWE: CVE-2019-11193
CPE: a:directadmin:directadmin
Platforms Tested:
2019
DirectAdmin Multiple Vulnerabilities to Takeover the Server <= v1.561
Multiple security vulnerabilities has been discovered in popular server control panel DirectAdmin, by InfinitumIT. Attackers can combine those security vulnerabilities and do a lot of critical action like server control takeover. Those vulnerabilities (Cross Site Scripting and Cross Site Request Forgery) may cause them to happen: Add administrator, execute command remote (RCE), Full Backup the Server and Upload the Own Server, webshell upload and more.
Mitigation:
Update to the latest version of DirectAdmin