VYPR

Kloxo

by Lxcenter

Source repositories

CVEs (2)

  • CVE-2014-125123CriJul 31, 2025
    risk 0.68cvss epss 0.01

    An unauthenticated SQL injection vulnerability exists in the Kloxo web hosting control panel (developed by LXCenter) prior to version 6.1.12. The flaw resides in the login-name parameter passed to lbin/webcommand.php, which fails to properly sanitize input, allowing an attacker…

  • CVE-2012-10022HigAug 1, 2025
    risk 0.58cvss epss 0.00

    Kloxo versions 6.1.12 and earlier contain two setuid root binaries—lxsuexec and lxrestart—that allow local privilege escalation from uid 48. The lxsuexec binary performs a uid check and permits execution of arbitrary commands as root if the invoking user matches uid 48. This…