Skip to main content

Vendor archive

gplhost CVEs

Beta · best-effort

16 CVEs tagged to vendor gplhost0 Critical, 4 High, 9 Medium, 3 Low, 0 Unrated.

CVE-2011-5276

Published Mar 21, 2014

SQL injection vulnerability in the drawAdminTools_PackageInstaller function in shared/inc/forms/packager.php in Domain Technologie Control (DTC) before 0.32.11 allows remote authe…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5275

Published Mar 21, 2014

The install script in Domain Technologie Control (DTC) before 0.34.1 gives sudo permissions for chrootuid to the dtc user, which makes it easier for context-dependent users to gai…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-5274

Published Mar 21, 2014

The drawAdminTools_PackageInstaller function in shared/inc/forms/packager.php in Domain Technologie Control (DTC) before 0.32.11 allows remote attackers to execute arbitrary comma…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-5273

Published Mar 21, 2014

Directory traversal vulnerability in shared/package-installer in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary PHP code via…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5272

Published Mar 21, 2014

SQL injection vulnerability in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary SQL commands via the vps_note parameter to dtc…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3199

Published Mar 21, 2014

Multiple cross-site scripting (XSS) vulnerabilities in Domain Technologie Control (DTC) before 0.34.1 allow remote authenticated users to inject arbitrary web script or HTML via t…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-3198

Published Mar 21, 2014

Domain Technologie Control (DTC) before 0.34.1 includes a password in the -b command line argument to htpasswd, which might allow local users to read the password by listing the p…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-3197

Published Mar 21, 2014

SQL injection vulnerability in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary SQL commands via the addrlink parameter to sha…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3196

Published Mar 21, 2014

The setup script in Domain Technologie Control (DTC) before 0.34.1 uses world-readable permissions for /etc/apache2/apache2.conf, which allows local users to obtain the dtcdaemons…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-3195

Published Mar 21, 2014

shared/inc/sql/lists.php in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in mailing list…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0437

Published Mar 7, 2011

shared/inc/sql/ssh.php in the SSH accounts management implementation in Domain Technologie Control (DTC) before 0.32.9 allows remote authenticated users to delete arbitrary accoun…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0436

Published Mar 7, 2011

The register_user function in client/new_account_form.php in Domain Technologie Control (DTC) before 0.32.9 includes a cleartext password in an e-mail message, which makes it easi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0435

Published Mar 7, 2011

Domain Technologie Control (DTC) before 0.32.9 does not require authentication for (1) admin/bw_per_month.php and (2) client/bw_per_month.php, which allows remote attackers to obt…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0434

Published Mar 7, 2011

Multiple SQL injection vulnerabilities in Domain Technologie Control (DTC) before 0.32.9 allow remote attackers to execute arbitrary SQL commands via the cid parameter to (1) admi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0402

Published Feb 3, 2009

SQL injection vulnerability in client/new_account.php in Domain Technologie Control (DTC) before 0.29.16 allows remote attackers to execute arbitrary SQL commands via the (1) fami…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-4951

Published Nov 5, 2008

dtc 0.29.6 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/awstats.log, (b) /tmp/spam.log.#####, and (c) /tmp/spam_err.log temporary files, relate…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1