VestaCP versions 0.9.8-22 and below suffer from multiple cross site scripting vulnerabilities.
7467ba2804d2b29e8b8284ec7982fe323b4a208a86a9eca0cbc3bfd8757f194e
VestaCP version 0.9.8 suffers from a command injection vulnerability.
938b6d6c27f61c9809c0637869f486e2fe7cb522a5ec286367a8f2f9bb53eebb
VestaCP version 0.9.8 suffers from a persistent cross site scripting vulnerability. Original discovery of persistent cross site scripting was discovered in this version in February of 2016 by Necmettin COSKUN.
936b7288bed9dcf93c8a516f91cad5a07fbe2daf994ea79501c73aef2e6153aa
VestaCP version 0.9.8 suffers from a cross site request forgery that can be leveraged to add remote ssh access.
d8e5b5595824f47b497814f48567128c28abd86490a24820989a572b16eb6f54
VestaCP version 0.9.8-26 suffers from an insufficient session validation vulnerability.
6159b79ee1c4557d55f413617ee3f2dcdd0659e7afec203a8cd037f6b89243be
VestaCP version 0.9.8-26 suffers from a cross site scripting vulnerability.
7e70fa744d9b07edcbfc4a161a26c921eb4218063ebaa6d7a2d8da58ea7d7db7
This Metasploit module exploits an authenticated command injection vulnerability in the v-list-user-backups bash script file in Vesta Control Panel to gain remote code execution as the root user.
a64694c4be6f8e142202272067ab8240d23b31e8f44348ffeb1c7d3cbe55c1cf
This Metasploit module exploits command injection vulnerability in v-list-user-backups bash script file. Low privileged authenticated users can execute arbitrary commands under the context of the root user. An authenticated attacker with a low privileges can inject a payload in the file name starts with dot. During the user backup process, this file name will be evaluated by the v-user-backup bash scripts. As result of that backup process, when an attacker try to list existing backups injected payload will be executed.
c994018871aaf2d9fb2b0d77fe7087abdbe4671491c2b25721371a3f880b91c3
Vesta Control Panel versions 0.9.7 through 0.9.8-16 suffer from a local privilege escalation vulnerability.
92b3241e8441af834584c0d465c45d6ae5c0868954554b3b59ef1a096edb42da
Vesta Control Panel versions 0.9.8-15 and below suffer from a persistent cross site scripting vulnerability via the user agent.
d430afd4621b5d62dad4b70ffff8d6258610f314f51abde198f22b3b9841fd8d