← Back

CVE-2017-17384

nvd nist
Published: Dec 7, 2017Modified: May 13, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job.

Affected (56)

Products: Ispconfig: Ispconfig
1 product
Ispconfig
Configuration A
56 vulnerable
Vulnerable SoftwareAffected Versions
Ispconfig
Version 3.0.2.1
Version 3.0.2.2
Version 3.0.2.2 b1
Version 3.0.2
Version 3.0.3.1
Version 3.0.3.1 rc1
Version 3.0.3.1 rc2
Version 3.0.3.2
Version 3.0.3.2 rc1
Version 3.0.3.3
Version 3.0.3.3 rc1
Version 3.0.3
Version 3.0.3 b1
Version 3.0.3 rc1
Version 3.0.4.1
Version 3.0.4.1 rc1
Version 3.0.4.1 rc2
Version 3.0.4.2
Version 3.0.4.3
Version 3.0.4.6
Version 3.0.4.6 rc1
Version 3.0.4
Version 3.0.4 b1
Version 3.0.5.1
Version 3.0.5.2
Version 3.0.5.3
Version 3.0.5.4
Version 3.0.5.4 b1
Version 3.0.5.4 p1
Version 3.0.5.4 p2
Version 3.0.5.4 p3
Version 3.0.5.4 p4
Version 3.0.5.4 p5
Version 3.0.5.4 p6
Version 3.0.5.4 p7
Version 3.0.5.4 p8
Version 3.0.5.4 p9
Version 3.0.5.4 rc1
Version 3.0.5.4 rc2
Version 3.0.5
Version 3.0.5 alpha1
Version 3.0.5 b1
Version 3.0.5 rc1
Version 3.0.5 rc2
Version 3.1.1
Version 3.1.1 p1
Version 3.1.2
Version 3.1.3
Version 3.1.4
Version 3.1.5
Version 3.1.6
Version 3.1.7
Version 3.1.7 p1
Version 3.1.8
Version 3.1.8 p1
Version 3.1

References (2)

Source: cve@mitre.org
Issue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchVendor Advisory

Timeline

No history available yet.