Gplhost develops Domain Technologie Control (DTC), a hosting control-panel suite for managing domains, mail services, and virtual hosting infrastructure. Its vulnerability profile centers on application-layer input handling and authentication weaknesses, with recurring disclosures around SQL injection, improper input validation, path traversal, and link-following flaws that are characteristic of legacy web-based administrative interfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gplhost over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-5275HIGH The install script in Domain Technologie Control (DTC) before 0.34.1 gives sudo permissions for chrootuid to the dtc user, which makes it easier for context-dependent users to gain | Mar 21, 2014 | 7.5 | 23 | NO | NO |
CVE-2011-5274HIGH The drawAdminTools_PackageInstaller function in shared/inc/forms/packager.php in Domain Technologie Control (DTC) before 0.32.11 allows remote attackers to execute arbitrary comman | Mar 21, 2014 | 7.5 | 23 | NO | NO |
CVE-2011-0434HIGH Multiple SQL injection vulnerabilities in Domain Technologie Control (DTC) before 0.32.9 allow remote attackers to execute arbitrary SQL commands via the cid parameter to (1) admin | Mar 7, 2011 | 7.5 | 23 | NO | NO |
CVE-2011-5272MEDIUM SQL injection vulnerability in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary SQL commands via the vps_note parameter to dtca | Mar 21, 2014 | 6.5 | 22 | NO | NO |
CVE-2011-5276MEDIUM SQL injection vulnerability in the drawAdminTools_PackageInstaller function in shared/inc/forms/packager.php in Domain Technologie Control (DTC) before 0.32.11 allows remote authen | Mar 21, 2014 | 6.5 | 21 | NO | NO |
CVE-2011-3195MEDIUM shared/inc/sql/lists.php in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in mailing list | Mar 21, 2014 | 6.5 | 21 | NO | NO |
CVE-2011-5273MEDIUM Directory traversal vulnerability in shared/package-installer in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary PHP code via | Mar 21, 2014 | 6.5 | 20 | NO | NO |
CVE-2011-3197MEDIUM SQL injection vulnerability in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary SQL commands via the addrlink parameter to shar | Mar 21, 2014 | 6.5 | 20 | NO | NO |
CVE-2009-0402HIGH SQL injection vulnerability in client/new_account.php in Domain Technologie Control (DTC) before 0.29.16 allows remote attackers to execute arbitrary SQL commands via the (1) famil | Feb 3, 2009 | 7.5 | 19 | NO | NO |
CVE-2011-0436MEDIUM The register_user function in client/new_account_form.php in Domain Technologie Control (DTC) before 0.32.9 includes a cleartext password in an e-mail message, which makes it easie | Mar 7, 2011 | 5.0 | 18 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gplhost.
Media articles that mention a CVE ID that affects a product developed by Gplhost — matched by CVE ID, not by vendor name.