CVE-2015-4117: Vestacp Control Panel
High severity, CVSS 8.8. EPSS: 10.6% chance of exploitation in the next 30 days.
Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter to list/backup/index.php.
Affected products
- Vestacp Control Panel: before 0.9.8-14 (fixed in 0.9.8-14)
Published 2018-02-28. Last modified 2026-06-17.