CVE-2017-17384

ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 65%
VendorProductVersion
ispconfigispconfig
3.0.2
ispconfigispconfig
3.0.2.1
ispconfigispconfig
3.0.2.2
ispconfigispconfig
3.0.2.2:b1
ispconfigispconfig
3.0.3
ispconfigispconfig
3.0.3:b1
ispconfigispconfig
3.0.3:rc1
ispconfigispconfig
3.0.3.1
ispconfigispconfig
3.0.3.1:rc1
ispconfigispconfig
3.0.3.1:rc2
ispconfigispconfig
3.0.3.2
ispconfigispconfig
3.0.3.2:rc1
ispconfigispconfig
3.0.3.3
ispconfigispconfig
3.0.3.3:rc1
ispconfigispconfig
3.0.4
ispconfigispconfig
3.0.4:b1
ispconfigispconfig
3.0.4.1
ispconfigispconfig
3.0.4.1:rc1
ispconfigispconfig
3.0.4.1:rc2
ispconfigispconfig
3.0.4.2
ispconfigispconfig
3.0.4.3
ispconfigispconfig
3.0.4.6
ispconfigispconfig
3.0.4.6:rc1
ispconfigispconfig
3.0.5
ispconfigispconfig
3.0.5:alpha1
ispconfigispconfig
3.0.5:b1
ispconfigispconfig
3.0.5:rc1
ispconfigispconfig
3.0.5:rc2
ispconfigispconfig
3.0.5.1
ispconfigispconfig
3.0.5.2
ispconfigispconfig
3.0.5.3
ispconfigispconfig
3.0.5.4
ispconfigispconfig
3.0.5.4:b1
ispconfigispconfig
3.0.5.4:p1
ispconfigispconfig
3.0.5.4:p2
ispconfigispconfig
3.0.5.4:p3
ispconfigispconfig
3.0.5.4:p4
ispconfigispconfig
3.0.5.4:p5
ispconfigispconfig
3.0.5.4:p6
ispconfigispconfig
3.0.5.4:p7
ispconfigispconfig
3.0.5.4:p8
ispconfigispconfig
3.0.5.4:p9
ispconfigispconfig
3.0.5.4:rc1
ispconfigispconfig
3.0.5.4:rc2
ispconfigispconfig
3.1
ispconfigispconfig
3.1.1
ispconfigispconfig
3.1.1:p1
ispconfigispconfig
3.1.2
ispconfigispconfig
3.1.3
ispconfigispconfig
3.1.4
ispconfigispconfig
3.1.5
ispconfigispconfig
3.1.6
ispconfigispconfig
3.1.7
ispconfigispconfig
3.1.7:p1
ispconfigispconfig
3.1.8
ispconfigispconfig
3.1.8:p1
𝑥
= Vulnerable software versions