CVE-2020-10808: OS Command Injection
Vesta Control Panel (VestaCP) through 0.9.8-26 allows Command Injection via the schedule/backup Backup Listing Endpoint. The attacker must be able to create a crafted filename on the server, as demonstrated by an FTP session that renames .bashlogout to a .bashlogout' substring followed by shell metacharacters.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-10808?
CVE-2020-10808 is a command injection vulnerability in Vesta Control Panel (VestaCP) through version 0.9.8-26, which allows an attacker to execute arbitrary commands on the server.
How severe is CVE-2020-10808?
CVE-2020-10808 has a severity rating of 8.8 out of 10, indicating it is critical.
Which software versions are affected by CVE-2020-10808?
Vesta Control Panel (VestaCP) versions up to and including 0.9.8-26 are affected by CVE-2020-10808.
How can an attacker exploit CVE-2020-10808?
An attacker can exploit CVE-2020-10808 by creating a crafted file name on the server, such as during an FTP session, which can then be used for command injection.
Are there any known fixes for CVE-2020-10808?
At the moment, there are no known fixes or patches available for CVE-2020-10808. It is recommended to update to the latest version of Vesta Control Panel when a patch becomes available.