WebDAV User Management Issue in ISPConfig by ISPConfig
CVE-2012-2087
9.8CRITICAL
What is CVE-2012-2087?
The vulnerability in ISPConfig version 3.0.4.3 arises from a flaw in the 'Add new WebDAV user' feature, which permits remote users to execute dangerous commands like chmod and chown from the client interface. This could lead to significant permission changes across the entire server, allowing unauthorized access and modifications. As a result, it is critical for users of the affected version to apply relevant patches and ensure proper server configurations to mitigate potential exploitation.
Affected Version(s)
ISPConfig 3.0.4.3