Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

CVE-2009-1525

CVE information

Published

14 years ago

Last Modified

6 years ago

CVSSv2.0 Severity

High

Impact Analysis

Description

CMD_DB in JBMC Software DirectAdmin before 1.334 allows remote authenticated users to gain privileges via shell metacharacters in the name parameter during a restore action..

CVSSv2.0 Score

Severity
High
Base Score
8.5/10
Exploit Score
6.8/10
Access Vector
Network
Access Complexity
Medium
Authentication Required
Single
Impact Score
10/10
Confidentiality Impact
Complete
Availability Impact
Complete
Integrity Impact
Complete

Products Affected

CPE Affected Vulnerable Excluding Edit
cpe:2.3:a:jbmc-software:directadmin:1.16:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.02:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.17:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.282:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.235:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.231:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.05:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.281:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.255:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.205:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.332:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.192:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.221:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.23:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.232:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.12:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.204:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.264:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.291:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.111:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.225:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.28:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:*:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.172:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.286:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.244:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.315:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.253:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.313:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.081:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.201:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.19:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.224:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.211:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.261:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.13:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.222:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.293:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.29:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.1941:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.193:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.251:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.31:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.252:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.242:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.213:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.312:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.203:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.273:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.1741:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.202:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.21:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.266:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.15:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.22:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.26:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.181:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.294:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.24:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.06:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.27:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.243:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.302:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:0.95:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.151:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.331:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.14:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.3:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.195:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.08:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.33:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.212:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.03:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.323:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.1:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.174:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.297:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.196:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.18:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.241:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.275:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.263:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.234:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.292:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.32:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.09:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.262:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.311:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.321:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.285:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.2:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.322:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.04:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.171:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.173:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.226:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.01:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.274:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.161:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.11:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.233:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.206:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.152:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.295:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.07:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.296:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.25:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.223:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.314:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.121:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.301:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.265:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.207:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:jbmc-software:directadmin:1.254:*:*:*:*:*:*:*
  Yes
- -