Control-webpanel

Webpanel

85 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 26.48%
  • Veröffentlicht 16.07.2019 18:15:13
  • Zuletzt bearbeitet 21.11.2024 04:24:47

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, a cwpsrv-xxx cookie allows a normal user to craft and upload a session file to the /tmp directory, and use it to become the root user.

Exploit
  • EPSS 15.31%
  • Veröffentlicht 16.07.2019 17:15:12
  • Zuletzt bearbeitet 21.11.2024 04:25:20

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote attackers can bypass authentication in the login process by leveraging the knowledge of a valid username. The attacker must defeat an encoding that is not equivalent to ...

Exploit
  • EPSS 14.24%
  • Veröffentlicht 16.07.2019 17:15:12
  • Zuletzt bearbeitet 21.11.2024 04:24:49

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, the Login process allows attackers to check whether a username is valid by reading the HTTP response.

Exploit
  • EPSS 24.45%
  • Veröffentlicht 16.07.2019 17:15:12
  • Zuletzt bearbeitet 21.11.2024 04:24:47

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging knowledge of a valid username.

Exploit
  • EPSS 5.32%
  • Veröffentlicht 21.05.2019 18:29:00
  • Zuletzt bearbeitet 21.11.2024 04:22:23

XSS was discovered in CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.747 via the testacc/fileManager2.php fm_current_dir or filename parameter.

Exploit
  • EPSS 5.91%
  • Veröffentlicht 13.05.2019 15:29:03
  • Zuletzt bearbeitet 21.11.2024 04:21:05

CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version), 0.9.8.753 (Pro) and 0.9.8.807 (Pro) is vulnerable to Reflected XSS for the "Domain" field on the "DNS Functions > "Add DNS Zone" screen.

Exploit
  • EPSS 7.25%
  • Veröffentlicht 26.03.2019 16:29:01
  • Zuletzt bearbeitet 21.11.2024 04:48:27

CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.763 is vulnerable to Stored/Persistent XSS for the "Package Name" field via the add_package module parameter.

Exploit
  • EPSS 4.75%
  • Veröffentlicht 20.11.2018 19:29:01
  • Zuletzt bearbeitet 21.11.2024 03:56:34

CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter.

Exploit
  • EPSS 3.41%
  • Veröffentlicht 20.11.2018 19:29:01
  • Zuletzt bearbeitet 21.11.2024 03:56:34

CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demonstrated by changing the root password.

Exploit
  • EPSS 3.48%
  • Veröffentlicht 20.11.2018 19:29:01
  • Zuletzt bearbeitet 21.11.2024 03:56:34

CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as demonstrated by executing an arbitrary OS command.