<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:content="http://purl.org/rss/1.0/modules/content/"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>vestacp — LowEndSpirit DEV</title>
        <link>https://dev.lowendspirit.com/index.php?p=/</link>
        <pubDate>Fri, 05 Jun 2026 00:14:45 +0000</pubDate>
        <language>en</language>
            <description>vestacp — LowEndSpirit DEV</description>
    <atom:link href="https://dev.lowendspirit.com/index.php?p=/discussions/tagged/vestacp/feed.rss" rel="self" type="application/rss+xml"/>
    <item>
        <title>VestaCP - vulnerbility      CVE-2020-10808</title>
        <link>https://dev.lowendspirit.com/index.php?p=/discussion/938/vestacp-vulnerbility-cve-2020-10808</link>
        <pubDate>Wed, 22 Apr 2020 12:00:41 +0000</pubDate>
        <category>Industry News</category>
        <dc:creator>mikho</dc:creator>
        <guid isPermaLink="false">938@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>I'm late to the party but since we had a discussion last year about a major security incident involving VestaCP, I thought this was a proper topic to post.</p>

<p>If you haven't already secured your own installation of VestaCP, please do asap.</p>

<blockquote><div>
  <p>Vesta Control Panel (VestaCP) through 0.9.8-26 allows Command Injection via the schedule/backup Backup Listing Endpoint. The attacker must be able to create a crafted filename on the server, as demonstrated by an FTP session that renames .bash_logout to a .bash_logout' substring followed by shell metacharacters.</p>
</div></blockquote>

<p>Keep an eye out for updates here: <a href="https://forum.vestacp.com/viewforum.php?f=25" rel="nofollow">https://forum.vestacp.com/viewforum.php?f=25</a></p>

<p>I won't post links to blog posts about how to exploit it, I'm sure you who are interested will find them soon enough.</p>

<p>On a personal note, I liked VestaCP, it was a nice, simple panel that had the features that I needed for my daily web hosting (personal) business....</p>

<p>Today, I don't need more things giving me headaches and trouble sleeping at night.</p>
]]>
        </description>
    </item>
   </channel>
</rss>
