Lucene search

K

Webuzo Security Vulnerabilities

cve
cve

CVE-2013-6041

index.php in Softaculous Webuzo before 2.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in a SOFTCookies sid cookie within a login action.

7.8AI Score

0.007EPSS

2014-12-27 06:59 PM
30
cve
cve

CVE-2013-6042

Cross-site scripting (XSS) vulnerability in filemanager/login.php in the File Manager module in Softaculous Webuzo before 2.1.4 allows remote attackers to inject arbitrary web script or HTML via the user parameter.

5.8AI Score

0.002EPSS

2013-11-19 04:50 AM
21
cve
cve

CVE-2013-6043

The login function in Softaculous Webuzo before 2.1.4 provides different error messages for invalid authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of requests.

7AI Score

0.003EPSS

2014-12-27 06:59 PM
21
cve
cve

CVE-2021-40238

A Cross Site Scriptiong (XSS) vulnerability exists in the admin panel in Webuzo < 2.9.0 via an HTTP request to a non-existent page, which is activated by administrators viewing the "Error Log" page. An attacker can leverage this to achieve Unauthenticated Remote Code Execution via the "Cron Jobs...

6.1CVSS

6.3AI Score

0.002EPSS

2021-09-15 05:15 PM
20