VendorsSoftaculouswebuzoany version
Vulnerabilities

Softaculous Webuzo any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2024-24621
Softaculous Webuzo Authentication Bypass
Published 2024-07-25 · Modified
10.0EPSS 0.012
CVE-2024-24622
Softaculous Webuzo Password Reset Command Injection
Published 2024-07-25 · Modified
9.0EPSS 0.019
CVE-2024-24623
Softaculous Webuzo FTP Management Command Injection
Published 2024-07-25 · Modified
9.0EPSS 0.019
CVE-2013-6041
index.php in Softaculous Webuzo before 2.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in a SOFTCookies sid cookie within a login action.
Published 2014-12-27 · Modified
7.51 PoCEPSS 0.036
CVE-2013-6043
The login function in Softaculous Webuzo before 2.1.4 provides different error messages for invalid authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of requests.
Published 2014-12-27 · Modified
5.01 PoCEPSS 0.029
CVE-2013-6042
Cross-site scripting (XSS) vulnerability in filemanager/login.php in the File Manager module in Softaculous Webuzo before 2.1.4 allows remote attackers to inject arbitrary web script or HTML via the user parameter.
Published 2013-11-15 · Modified
4.31 PoCEPSS 0.017