Softaculous
Softaculous Webuzo: vulnerabilidades y CVE
Softaculous Webuzo tiene 6 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-24623 | Alta (8.8) | 1.9% | — | 25 jul 2024 | Softaculous Webuzo contains a command injection vulnerability in the FTP management functionality. A remote, authenticated attacker can exploit this vulnerability to gain code execution on the system. |
| CVE-2024-24622 | Alta (8.8) | 1.9% | — | 25 jul 2024 | Softaculous Webuzo contains a command injection in the password reset functionality. A remote, authenticated attacker can exploit this vulnerability to gain code execution on the system. |
| CVE-2024-24621 | Crítica (9.8) | 1.2% | — | 25 jul 2024 | Softaculous Webuzo contains an authentication bypass vulnerability through the password reset functionality. Remote, anonymous attackers can exploit this vulnerability to gain full server access as the root user. |
| CVE-2013-6043 | Media (5) | 2.9% | — | 27 dic 2014 | The login function in Softaculous Webuzo before 2.1.4 provides different error messages for invalid authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate… |
| CVE-2013-6041 | Alta (7.5) | 3.6% | — | 27 dic 2014 | index.php in Softaculous Webuzo before 2.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in a SOFTCookies sid cookie within a login action. |
| CVE-2013-6042 | Media (4.3) | 1.6% | — | 19 nov 2013 | Cross-site scripting (XSS) vulnerability in filemanager/login.php in the File Manager module in Softaculous Webuzo before 2.1.4 allows remote attackers to inject arbitrary web script or HTML via the user parameter. |