Cross-site scripting (XSS) vulnerability in JBMC Software DirectAdmin before 1.293 does not properly display log files, which allows remote authenticated users to inject arbitrary web script or HTML via (1) http or (2) ftp requests logged in /var/log/directadmin/security.log; (3) allows context-dependent attackers to inject arbitrary web script or HTML into /var/log/messages via a PHP script that invokes /usr/bin/logger; (4) allows local users to inject arbitrary web script or HTML into /var/log/messages by invoking /usr/bin/logger at the command line; and allows remote attackers to inject arbitrary web script or HTML via remote requests logged in the (5) /var/log/exim/rejectlog, (6) /var/log/exim/mainlog, (7) /var/log/proftpd/auth.log, (8) /var/log/httpd/error_log, (9) /var/log/httpd/access_log, (10) /var/log/directadmin/error.log, and (11) /var/log/directadmin/security.log files.
History

Tue, 16 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Directadmin
Directadmin directadmin
Weaknesses NVD-CWE-Other CWE-79
CPEs cpe:2.3:a:jbmc_software:directadmin:*:*:*:*:*:*:*:* cpe:2.3:a:directadmin:directadmin:*:*:*:*:*:*:*:*
Vendors & Products Jbmc Software
Jbmc Software directadmin
Directadmin
Directadmin directadmin

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T13:13:41.640Z

Reserved: 2007-04-10T00:00:00

Link: CVE-2007-1926

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2007-04-10T23:19:00.000

Modified: 2025-12-16T21:08:20.230

Link: CVE-2007-1926

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.