SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2005-0794

ZPanel 2.0 and 2.5 beta 10 does not remove or protect installation scripts after they have been used, which allows remote attackers to reinstall the software and possibly cause a denial of service via a direct request to install.php.

MEDIUM 6.4EPSS 1.55%

Does this matter?

Lower severity and a low EPSS score (1.55%). Track it; it rarely justifies an emergency change on its own.

Description

ZPanel 2.0 and 2.5 beta 10 does not remove or protect installation scripts after they have been used, which allows remote attackers to reinstall the software and possibly cause a denial of service via a direct request to install.php.

CVSS 2.0
6.4 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
EPSS
1.55% probability · 74th percentile
CISA KEV
Not listed
Affected
zpanel/zpanel
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.