CVE-2015-4117: OS Command Injection
Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter to list/backup/index.php.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-4117?
CVE-2015-4117 is a vulnerability in Vesta Control Panel before version 0.9.8-14 that allows remote authenticated users to execute arbitrary commands via shell metacharacters.
How severe is CVE-2015-4117?
CVE-2015-4117 has a severity rating of 8.8, which is considered high.
How does CVE-2015-4117 affect Vesta Control Panel?
CVE-2015-4117 affects Vesta Control Panel versions up to and excluding 0.9.8-14.
How can I fix CVE-2015-4117?
To fix CVE-2015-4117, you should update your Vesta Control Panel to version 0.9.8-14 or later.
Where can I find more information about CVE-2015-4117?
You can find more information about CVE-2015-4117 in the references provided: [http://vestacp.com/roadmap/#history](http://vestacp.com/roadmap/#history), [https://www.exploit-db.com/exploits/37369/](https://www.exploit-db.com/exploits/37369/), [https://www.htbridge.com/advisory/HTB23261](https://www.htbridge.com/advisory/HTB23261).