← Vulnerability feed

Vulnerability record · CVE-2018-1000081 · published 13 March 2018

CVE-2018-1000081: Ajenti improper input validation vulnerability

Ajenti · Ajenti

Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter ..

7.5 CVSS 3.0 High EPSS 1.1% · top 35.2% CWE-20 · Improper input validation
7.5CVSS 3.0 base score, v2 5.0
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter ..

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-1000081 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2019-25066Ajenti improper privilege management vulnerabilityA vulnerability has been found in ajenti 2.1.31 and classified as critical. This vulnerability affects unknown code of the component API. The manipul…EPSS 5.4%8.8CVE-2018-1000082Ajenti cross-site request forgery vulnerabilityAjenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the serv…EPSS 1.3%8.1CVE-2026-27975Ajenti improper access control vulnerabilityAjenti is a Linux and BSD modular server admin panel. Prior to version 2.2.13, an unauthenticated user could gain access to a server to execute arbit…EPSS 0.67%7.5CVE-2018-1000126Ajenti information exposure vulnerabilityAjenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as we…EPSS 1.6%7.2CVE-2026-35175Ajenti missing authorization vulnerabilityAjenti is a Linux and BSD modular server admin panel. Prior to 2.2.15, an authenticated user (using the auth_users plugin authentication method) coul…EPSS 0.38%6.5CVE-2018-1000080Ajenti incorrect permission assignment vulnerabilityAjenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a …EPSS 0.84%5.3CVE-2018-1000083Ajenti path traversal vulnerabilityAjenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of th…EPSS 1.5%4.3CVE-2014-4301Ajenti cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in the respond_error function in routing.py in Eugene Pankov Ajenti before 1.2.21.7 allow remote …EPSS 2.3%

Source: NIST National Vulnerability Database (record CVE-2018-1000081), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.