Skip to content
Noroxi

control-webpanel records

85 published records for vendor control-webpanel.

All records

85 records
  • login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS comma

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    control-webpanel · webpanelJan 5, 2023

  • CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in t

    CriticalCVSS 9.0KEVWeaponizedEPSS 100%

    control-webpanel · webpanelSep 19, 2025

  • CVE-2021-45467
    60This week

    In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.ph

    CriticalCVSS 9.8Proof of conceptEPSS 71%

    control-webpanel · webpanelDec 26, 2022

  • A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request.

    CriticalCVSS 9.8No exploitEPSS 57%

    control-webpanel · webpanelJul 7, 2022

  • In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to a

    CriticalCVSS 9.8No exploitEPSS 55%

    control-webpanel · webpanelDec 26, 2022

  • CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/index.php?module=fil

    HighCVSS 7.5Proof of conceptEPSS 71%

    control-webpanel · webpanelOct 15, 2018

  • The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution

    CriticalCVSS 9.8Proof of conceptEPSS 35%

    control-webpanel · webpanelMay 18, 2021

  • In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging k

    CriticalCVSS 9.8Proof of conceptEPSS 24%

    control-webpanel · webpanelJul 16, 2019

  • CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php t

    CriticalCVSS 9.8Proof of conceptEPSS 16%

    control-webpanel · webpanelMar 16, 2020

  • CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php service_start

    CriticalCVSS 9.8Proof of conceptEPSS 15%

    control-webpanel · webpanelOct 15, 2018

  • The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.

    CriticalCVSS 9.8Proof of conceptEPSS 13%

    control-webpanel · webpanelMay 18, 2021

  • This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.

    CriticalCVSS 9.8No exploitEPSS 8%

    control-webpanel · webpanelJul 28, 2020

  • This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.

    CriticalCVSS 9.8No exploitEPSS 8%

    control-webpanel · webpanelJul 28, 2020

  • This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.

    CriticalCVSS 9.8No exploitEPSS 8%

    control-webpanel · webpanelJul 28, 2020

  • This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.

    CriticalCVSS 9.8No exploitEPSS 8%

    control-webpanel · webpanelJul 28, 2020

  • This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.

    CriticalCVSS 9.8No exploitEPSS 8%

    control-webpanel · webpanelJul 28, 2020

  • This vulnerability allows remote attackers to write arbitrary files on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.

    CriticalCVSS 9.8No exploitEPSS 8%

    control-webpanel · webpanelJul 28, 2020

  • Command injection vulnerability in CWP v0.9.8.1126 that allows normal users to run commands as the root user.

    HighCVSS 8.8No exploitEPSS 20%

    control-webpanel · webpanelJul 7, 2022

  • This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.

    CriticalCVSS 9.8No exploitEPSS 8%

    control-webpanel · webpanelJul 28, 2020

  • This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-el7-0.9.8.891.

    CriticalCVSS 9.8No exploitEPSS 8%

    control-webpanel · webpanelJul 28, 2020

  • This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.

    CriticalCVSS 9.8No exploitEPSS 8%

    control-webpanel · webpanelJul 28, 2020

  • This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.

    CriticalCVSS 9.8No exploitEPSS 8%

    control-webpanel · webpanelJul 28, 2020

  • This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.

    CriticalCVSS 9.8No exploitEPSS 8%

    control-webpanel · webpanelJul 28, 2020

  • This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.

    CriticalCVSS 9.8No exploitEPSS 8%

    control-webpanel · webpanelJul 28, 2020

  • This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.

    CriticalCVSS 9.8No exploitEPSS 8%

    control-webpanel · webpanelJul 28, 2020