An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if adminallowlangedit is enabled.
ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface.
ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution
Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7 allow remote attackers to hijack the authentication of (1) administrators for requests that create an administrator account via a request to admin/usersedit.php or (2) arbitrary users for requests that conduct SQL injection attacks via the server parameter to monitor/showsysstate.php.
SQL injection vulnerability in monitor/showsysstate.php in ISPConfig before 3.0.5.4p7 allows remote authenticated users with monitor permissions to execute arbitrary SQL commands via the server parameter. NOTE: this can be leveraged by remote attackers using CVE-2015-4119.2.
An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code execution. This is exploitable by authenticated users who have local filesystem access.