CVE-2005-1932
Estado: ModificadaBaja (2.1)—
Lpanel 1.59 and earlier, and other versions before 1.597, allows remote authenticated users to modify certain critical variables and (1) modify DNS settings for arbitrary domains via the domain parameter to diagnose.php, (2) close, open, or respond to arbitrary support tickets via the close, open, or pid parameter to view_ticket.php, (3) obtain sensitive information on arbitrary invoices via the inv parameter to viewreceipt.php, or (4) modify domain information for arbitrary domains via the editdomain parameter to domains.php.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N
- Puntuación base: 2.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.73%
- Percentil entre todas las CVEs puntuadas: 53
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034414.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034415.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034416.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034417.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034418.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034419.html
- http://secunia.com/advisories/15589/
- http://www.lpanel.net/changelog.php
- http://www.securityfocus.com/bid/13869
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034414.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034415.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034416.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034417.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034418.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034419.html
- http://secunia.com/advisories/15589/
- http://www.lpanel.net/changelog.php
- http://www.securityfocus.com/bid/13869
JSON original (NVD)
Mostrar
{
"id": "CVE-2005-1932",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.1,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2005-07-05T04:00:00.000",
"references": [
{
"url": "http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034414.html",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034415.html",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034416.html",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034417.html",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034418.html",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034419.html",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/15589/",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.lpanel.net/changelog.php",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/13869",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034414.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034415.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034416.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034417.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034418.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034419.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/15589/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.lpanel.net/changelog.php",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/13869",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Lpanel 1.59 and earlier, and other versions before 1.597, allows remote authenticated users to modify certain critical variables and (1) modify DNS settings for arbitrary domains via the domain parameter to diagnose.php, (2) close, open, or respond to arbitrary support tickets via the close, open, or pid parameter to view_ticket.php, (3) obtain sensitive information on arbitrary invoices via the inv parameter to viewreceipt.php, or (4) modify domain information for arbitrary domains via the editdomain parameter to domains.php."
}
],
"lastModified": "2026-06-16T22:13:56.410",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:lpanel:lpanel:1.59:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "023B1268-93B7-4ABC-B0D6-08B0F185BD04"
},
{
"criteria": "cpe:2.3:a:lpanel:lpanel:1.593:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AF3C1988-84E8-4931-9E42-20667CA997C6"
},
{
"criteria": "cpe:2.3:a:lpanel:lpanel:1.594:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B74E52EE-9A94-4F52-B5FC-397B7682C01A"
},
{
"criteria": "cpe:2.3:a:lpanel:lpanel:1.596:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A6B779FE-C7CE-4F05-A937-B9AFCE5C3419"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}