Cross-site scripting (XSS) vulnerability in JBMC Software DirectAdmin before 1.293 does not properly display log files, which allows remote authenticated users to inject arbitrary web script or HTML via (1) http or (2) ftp requests logged in /var/log/directadmin/security.log; (3) allows context-dependent attackers to inject arbitrary web script or HTML into /var/log/messages via a PHP script that invokes /usr/bin/logger; (4) allows local users to inject arbitrary web script or HTML into /var/log/messages by invoking /usr/bin/logger at the command line; and allows remote attackers to inject arbitrary web script or HTML via remote requests logged in the (5) /var/log/exim/rejectlog, (6) /var/log/exim/mainlog, (7) /var/log/proftpd/auth.log, (8) /var/log/httpd/errorlog, (9) /var/log/httpd/accesslog, (10) /var/log/directadmin/error.log, and (11) /var/log/directadmin/security.log files.
Multiple cross-site scripting (XSS) vulnerabilities in JBMC Software DirectAdmin 1.28.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) user parameter to (a) CMDSHOWRESELLER or (b) CMDSHOWUSER in the Admin level; the (2) TYPE parameter to (c) CMDTICKETCREATE or (d) CMDTICKET, the (3) user parameter to (e) CMDEMAILFORWARDERMODIFY, (f) CMDEMAILVACATIONMODIFY, or (g) CMDFTPSHOW, and the (4) name parameter to (h) CMDEMAILLIST in the User level; or the (5) user parameter to (i) CMDSHOWUSER in the Reseller level.
Cross-site scripting (XSS) vulnerability in HTMPASSWD in DirectAdmin Hosting Management allows remote attackers to inject arbitrary web script or HTML via the domain parameter.
Cross-site scripting (XSS) vulnerability in CMDUSERSTATS in DirectAdmin allows remote attackers to inject arbitrary web script or HTML via the RESULT parameter, a different vector than CVE-2006-5983.