VYPR

Cwp

by Centos Web Panel

CVEs (10)

  • CVE-2020-10230CriMar 16, 2020
    risk 0.68cvss 9.8epss 0.15

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php term parameter.

  • CVE-2018-18322CriOct 15, 2018
    risk 0.68cvss 9.8epss 0.15

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php service_start, service_restart, service_fullstatus, or service_stop parameter.

  • CVE-2018-18773HigNov 20, 2018
    risk 0.60cvss 8.8epss 0.03

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demonstrated by changing the root password.

  • CVE-2018-18324MedOct 15, 2018
    risk 0.43cvss 6.1epss 0.03

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has XSS via the admin/fileManager2.php fm_current_dir parameter, or the admin/index.php module, service_start, service_fullstatus, service_restart, service_stop, or file (within the file_editor) parameter.

  • CVE-2018-5961MedJan 22, 2018
    risk 0.40cvss 6.1epss 0.03

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel through v0.9.8.12 has XSS via the `module` value of the `index.php` file.

  • CVE-2019-13599MedAug 21, 2019
    risk 0.35cvss 5.3epss 0.04

    In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.848, the Login process allows attackers to check whether a username is valid by comparing response times.

  • CVE-2019-7646MedMar 26, 2019
    risk 0.35cvss 4.8epss 0.07

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.763 is vulnerable to Stored/Persistent XSS for the "Package Name" field via the add_package module parameter.

  • CVE-2019-10893MedApr 18, 2019
    risk 0.34cvss 4.8epss 0.03

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version) and 0.9.8.753 (Pro) is vulnerable to Stored/Persistent XSS for Admin Email fields on the "CWP Settings > "Edit Settings" screen. By changing the email ID to any XSS Payload and clicking on Save…

  • CVE-2019-14728MedSep 10, 2019
    risk 0.28cvss 4.3epss 0.01

    In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to add an e-mail forwarding destination to a victim's account via an attacker account.

  • CVE-2019-14722MedSep 10, 2019
    risk 0.28cvss 4.3epss 0.02

    In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete an e-mail forwarding destination from a victim's account via an attacker account.