CVE-2012-2087: Critical severity ispconfig vulnerability
Published Jan 23, 2020
·Updated
ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface.
Affected Software
1 affected component
ISPConfig ISPConfig=3.0.4.3
Event History
Jan 23, 2020
CVE Published
via MITRE·01:57 PM
Data Sourced
via MITRE·01:57 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2012-2087?
The severity of CVE-2012-2087 is critical with a value of 9.8.
2
What is affected by CVE-2012-2087?
ISPConfig version 3.0.4.3 is affected by CVE-2012-2087.
3
What can an attacker do with CVE-2012-2087?
An attacker can chmod and chown the entire server from the client interface using the 'Add new Webdav user' function in ISPConfig 3.0.4.3.
4
How can I fix CVE-2012-2087?
Update ISPConfig to a version that is not affected by CVE-2012-2087.
5
Where can I find more information about CVE-2012-2087?
You can find more information about CVE-2012-2087 at the following references: [link1](http://www.openwall.com/lists/oss-security/2012/04/08/3), [link2](http://www.openwall.com/lists/oss-security/2012/04/09/4), [link3](https://exchange.xforce.ibmcloud.com/vulnerabilities/74739).