← Vulnerability feed

Vulnerability record · CVE-2013-3629 · published 7 February 2020

CVE-2013-3629: Ispconfig vulnerability

Ispconfig · Ispconfig

ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution

8.8 CVSS 3.1 High EPSS 43% · top 1.3%
8.8CVSS 3.1 base score, v2 6.5
43%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-3629 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-3021Ispconfig sql injection vulnerabilityISPConfig before 3.2.2 allows SQL injection.EPSS 2.1%9.8CVE-2020-9398Ispconfig sql injection vulnerabilityISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQL Injection.EPSS 1.3%9.8CVE-2012-2087Ispconfig incorrect permission assignment vulnerabilityISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface.EPSS 2.7%8.8CVE-2017-17384Ispconfig improper privilege management vulnerabilityISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job.EPSS 1.5%7.8CVE-2018-17984Ispconfig vulnerabilityAn unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code execution. This …EPSS 3.4%7.5CVE-2006-3042Ispconfig vulnerabilityMultiple PHP remote file inclusion vulnerabilities in ISPConfig 2.2.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) go_in…EPSS 2.9%7.5CVE-2006-2315Ispconfig code injection vulnerabilityPHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a…EPSS 4.8%7.2CVE-2023-46818Ispconfig code injection vulnerabilityAn issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_lange…EPSS 16%

Source: NIST National Vulnerability Database (record CVE-2013-3629), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.