Linux sg77.dns-private.com 5.14.0-503.40.1.el9_5.x86_64 #1 SMP PREEMPT_DYNAMIC Mon May 5 06:06:04 EDT 2025 x86_64
LiteSpeed
Server IP : 135.181.230.13 & Your IP : 216.73.217.69
Domains :
Cant Read [ /etc/named.conf ]
User : pilasate
Terminal
Auto Root
Create File
Create Folder
Localroot Suggester
Backdoor Destroyer
Readme
/
var /
softaculous /
roundcube /
Delete
Unzip
Name
Size
Permission
Date
Action
images
[ DIR ]
drwxr-xr-x
2026-07-07 08:51
php53
[ DIR ]
drwxr-xr-x
2026-07-07 08:51
php56
[ DIR ]
drwxr-xr-x
2026-07-07 08:51
php71
[ DIR ]
drwxr-xr-x
2026-07-07 08:51
php81
[ DIR ]
drwxr-xr-x
2026-07-07 08:51
php82
[ DIR ]
drwxr-xr-x
2026-07-07 08:51
changelog.txt
2.38
KB
-rw-r--r--
2026-07-06 08:52
clone.php
3.4
KB
-rw-r--r--
2026-07-06 12:10
config.inc.php
3.9
KB
-rw-r--r--
2025-02-10 09:28
fileindex.php
203
B
-rw-r--r--
2021-12-23 11:54
import.php
3.29
KB
-rw-r--r--
2026-07-06 12:10
info.xml
2.94
KB
-rw-r--r--
2026-07-06 08:52
install.js
1.25
KB
-rw-r--r--
2021-12-23 11:54
install.php
6.51
KB
-rw-r--r--
2026-07-06 12:10
install.xml
3.73
KB
-rw-r--r--
2021-12-23 11:54
md5
2.46
KB
-rw-r--r--
2026-07-06 12:10
notes.txt
1.23
KB
-rw-r--r--
2023-07-03 10:47
remove.php
3.11
KB
-rw-r--r--
2026-07-06 12:10
upgrade.php
7.01
KB
-rw-r--r--
2026-07-06 12:10
upgrade.xml
341
B
-rw-r--r--
2021-12-23 11:54
Save
Rename
## Release 1.6.17 - Enigma: Support automatic public key lookup (import) using HKP v1 protocol (#5314) - Enigma: Kolab WOAT Support (#8626) - Security: Fix an infinite loop in TNEF (winmail.dat) decoder (#10193) - Security: Fix various vulnerabilities in the password plugin using session-injected username - Security: Fix stored XSS via unescaped attachment MIME type on the attachment-validation warning page [CVE-2026-54432] - Security: Fix SSRF bypass via specific local address URLs - two new cases - Security: Fix zero-click stored XSS in plain-text rendering [CVE-2026-54433] - Security: Fix DoS via crafted compressed-RTF size in the TNEF (winmail.dat) file ## Release 1.6.16 - Fix potential too long value in IMAP ID command (#10136) - Security: Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog - Security: Fix CSS injection bypass in HTML sanitizer via SVG `<animate attributeName="style">` - Security: Fix pre-auth SQL injection in `virtuser_query` plugin via preg_replace backslash escape bypass - Security: Fix SSRF bypass via specific local address URLs - Security: Fix bypass of remote image blocking via CSS var() - Security: Fix local/private URL fetch bypass when remote resources were not allowed - Security: Fix pre-auth arbitrary file delete via redis/memcache session poisoning bypass - Security: Fix code injection vulnerability - remove support for code evaluation in LDAP `autovalues` option ## Release 1.6.15 - Fix regression where mail search would fail on non-ascii search criteria (#10121) - Fix regression where some data url images could get ignored/lost (#10128) - Fix SVG Animate FUNCIRI Attribute Bypass — Remote Image Loading via fill/filter/stroke ## Release 1.6.14 - Fix Postgres connection using IPv6 address (#10104) - Security: Fix pre-auth arbitrary file write via unsafe deserialization in redis/memcache session handler - Security: Fix bug where a password could get changed without providing the old password - Security: Fix IMAP Injection + CSRF bypass in mail search - Security: Fix remote image blocking bypass via various SVG animate attributes - Security: Fix remote image blocking bypass via a crafted body background attribute - Security: Fix fixed position mitigation bypass via use of !important - Security: Fix XSS issue in a HTML attachment preview - Security: Fix SSRF + Information Disclosure via stylesheet links to a local network hosts