Control-webpanel

Webpanel

85 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 9.39%
  • Veröffentlicht 16.07.2019 18:15:13
  • Zuletzt bearbeitet 21.11.2024 04:24:47

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, a cwpsrv-xxx cookie allows a normal user to craft and upload a session file to the /tmp directory, and use it to become the root user.

Exploit
  • EPSS 4.62%
  • Veröffentlicht 16.07.2019 17:15:12
  • Zuletzt bearbeitet 21.11.2024 04:25:20

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote attackers can bypass authentication in the login process by leveraging the knowledge of a valid username. The attacker must defeat an encoding that is not equivalent to ...

Exploit
  • EPSS 20.74%
  • Veröffentlicht 16.07.2019 17:15:12
  • Zuletzt bearbeitet 21.11.2024 04:24:49

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, the Login process allows attackers to check whether a username is valid by reading the HTTP response.

Exploit
  • EPSS 27.3%
  • Veröffentlicht 16.07.2019 17:15:12
  • Zuletzt bearbeitet 21.11.2024 04:24:47

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging knowledge of a valid username.

Exploit
  • EPSS 0.21%
  • Veröffentlicht 21.05.2019 18:29:00
  • Zuletzt bearbeitet 21.11.2024 04:22:23

XSS was discovered in CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.747 via the testacc/fileManager2.php fm_current_dir or filename parameter.

Exploit
  • EPSS 0.35%
  • Veröffentlicht 13.05.2019 15:29:03
  • Zuletzt bearbeitet 21.11.2024 04:21:05

CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version), 0.9.8.753 (Pro) and 0.9.8.807 (Pro) is vulnerable to Reflected XSS for the "Domain" field on the "DNS Functions > "Add DNS Zone" screen.

Exploit
  • EPSS 0.38%
  • Veröffentlicht 26.03.2019 16:29:01
  • Zuletzt bearbeitet 21.11.2024 04:48:27

CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.763 is vulnerable to Stored/Persistent XSS for the "Package Name" field via the add_package module parameter.

Exploit
  • EPSS 2.2%
  • Veröffentlicht 20.11.2018 19:29:01
  • Zuletzt bearbeitet 21.11.2024 03:56:34

CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter.

Exploit
  • EPSS 0.36%
  • Veröffentlicht 20.11.2018 19:29:01
  • Zuletzt bearbeitet 21.11.2024 03:56:34

CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demonstrated by changing the root password.

Exploit
  • EPSS 0.51%
  • Veröffentlicht 20.11.2018 19:29:01
  • Zuletzt bearbeitet 21.11.2024 03:56:34

CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as demonstrated by executing an arbitrary OS command.