CVE-2013-10053 - CVE House
Back to Database
Status published High CVE-2013-10053

ZPanel <= 10.0.0.2 htpasswd Module Username Command Execution

Vulnerability Description

A remote command execution vulnerability exists in ZPanel version 10.0.0.2 in its htpasswd module. When creating .htaccess files, the inHTUsername field is passed unsanitized to a system() call that invokes the system’s htpasswd binary. By injecting shell metacharacters into the username field, an authenticated attacker can execute arbitrary system commands. Exploitation requires a valid ZPanel account—such as one in the default Users, Resellers, or Administrators groups—but no elevated privileges.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-10053

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • shachibista

Affected Vendor

ZPanel Project

View all reports →

Affected Software

ZPanel
Vulnerable Versions:
0

Timeline

Official Publish: August 1st, 2025
Last Modified: May 15th, 2026
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)