ajenti@1.2.21.0 vulnerabilities
The server administration panel
-
latest version
1.2.23.13
-
first published
11 years ago
-
latest version published
7 years ago
-
licenses detected
- [0,)
Direct Vulnerabilities
Known vulnerabilities in the ajenti package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
ajenti is a Linux & BSD web admin panel. Affected versions of this package are vulnerable to Remote Code Execution (RCE) in How to fix Remote Code Execution (RCE)? A fix was pushed into the |
[0,)
|
ajenti is a Linux & BSD web admin panel. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) attacks via a filename that is mishandled in File Manager. How to fix Cross-site Scripting (XSS)? There is no fix version for |
[0,)
|
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) attacks due to not validating user input passed into the |
[1.2.20.0,1.2.22.13)
|
Multiple Cross-site Scripting (XSS) vulnerabilities in the respond_error function in routing.py in Eugene Pankov Ajenti before 1.2.21.7 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) resources.js or (2) resources.css in ajenti:static/, related to the traceback page. |
[,1.2.21.6)
|