← Vulnerability feed

Vulnerability record · CVE-2015-4117 · published 28 February 2018

CVE-2015-4117: Vestacp control panel os command injection vulnerability

Vestacp · Control Panel

Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter to list/backup/index.php.

8.8 CVSS 3.0 High EPSS 11% · top 4.4% CWE-78 · OS command injection
8.8CVSS 3.0 base score, v2 6.5
11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter to list/backup/index.php.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-4117 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2019-12791Vestacp control panel path traversal vulnerabilityA directory traversal vulnerability in the v-list-user script in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular regist…EPSS 6.5%8.8CVE-2019-12792Vestacp control panel os command injection vulnerabilityA command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered us…EPSS 4.9%7.8CVE-2022-3967Vestacp control panel vulnerabilityA vulnerability, which was classified as critical, was found in Vesta Control Panel. Affected is an unknown function of the file func/main.sh of the …EPSS 0.23%7.8CVE-2021-30463Vestacp control panel link following vulnerabilityVestaCP through 0.9.8-24 allows attackers to gain privileges by creating symlinks to files for which they lack permissions. After reading the RKEY va…EPSS 0.50%7.2CVE-2021-46850Vestacp control panel argument injection vulnerabilitymyVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and remote adm…EPSS 5.4%6.5CVE-2020-10966Hestiacp control panel vulnerabilityIn the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header manipulation leads to account…EPSS 1.9%6.1CVE-2019-9841Vestacp control panel cross-site scripting vulnerabilityVesta Control Panel 0.9.8-23 allows XSS via a crafted URL.EPSS 1.3%6.1CVE-2018-18547Vestacp control panel cross-site scripting vulnerabilityVesta Control Panel through 0.9.8-22 has XSS via the edit/web/ domain parameter, the list/backup/ backup parameter, the list/rrd/ period parameter, t…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2015-4117), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.