Записи control-webpanel
85 опубликованных записей вендора control-webpanel.
Профиль для исследователя
- Попали в KEV
- 2 · 2,4 %
- С эксплойтом
- 2 · 2,4 %
- Pre-auth RCE
- 32
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- 29 дн.
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')33
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')14
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-639 Authorization Bypass Through User-Controlled Key5
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
85 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2022-44877Готовый эксплойт | login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commacontrol-webpanel · webpanel · CWE-78 | Критическая9,8 | KEV | 100,0 % | 5 янв. 2023 г. |
96Срочно | CVE-2025-48703Готовый эксплойт | CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in tcontrol-webpanel · webpanel · CWE-78 | Критическая9,0 | KEV | 99,7 % | 19 сент. 2025 г. |
60На этой неделе | CVE-2021-45467Proof of concept | In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.phcontrol-webpanel · webpanel · CWE-862 | Критическая9,8 | — | 70,7 % | 26 дек. 2022 г. |
56В плане | CVE-2022-25046Эксплойта нет | A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request.control-webpanel · webpanel · CWE-22 | Критическая9,8 | — | 57,4 % | 7 июл. 2022 г. |
56В плане | CVE-2021-45466Эксплойта нет | In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to acontrol-webpanel · webpanel · CWE-863 | Критическая9,8 | — | 55,3 % | 26 дек. 2022 г. |
51В плане | CVE-2018-18323Proof of concept | CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/index.php?module=filcontrol-webpanel · webpanel · CWE-22 | Высокая7,5 | — | 70,7 % | 15 окт. 2018 г. |
49В плане | CVE-2021-31324Proof of concept | The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Executioncontrol-webpanel · webpanel · CWE-78 | Критическая9,8 | — | 34,6 % | 18 мая 2021 г. |
46В плане | CVE-2019-13360Proof of concept | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging kcontrol-webpanel · webpanel · CWE-639 | Критическая9,8 | — | 24,5 % | 16 июл. 2019 г. |
44В плане | CVE-2020-10230Proof of concept | CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php tcontrol-webpanel · webpanel · CWE-89 | Критическая9,8 | — | 15,8 % | 16 мар. 2020 г. |
44В плане | CVE-2018-18322Proof of concept | CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php service_startcontrol-webpanel · webpanel · CWE-78 | Критическая9,8 | — | 15,1 % | 15 окт. 2018 г. |
43В плане | CVE-2021-31316Proof of concept | The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.control-webpanel · webpanel · CWE-89 | Критическая9,8 | — | 13,3 % | 18 мая 2021 г. |
42В плане | CVE-2020-15429Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Критическая9,8 | — | 8,4 % | 28 июл. 2020 г. |
42В плане | CVE-2020-15435Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Критическая9,8 | — | 8,4 % | 28 июл. 2020 г. |
42В плане | CVE-2020-15612Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Критическая9,8 | — | 8,4 % | 28 июл. 2020 г. |
42В плане | CVE-2020-15434Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Критическая9,8 | — | 8,4 % | 28 июл. 2020 г. |
42В плане | CVE-2020-15422Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Критическая9,8 | — | 8,4 % | 28 июл. 2020 г. |
42В плане | CVE-2020-15623Эксплойта нет | This vulnerability allows remote attackers to write arbitrary files on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-749 | Критическая9,8 | — | 8,3 % | 28 июл. 2020 г. |
41В плане | CVE-2022-25048Эксплойта нет | Command injection vulnerability in CWP v0.9.8.1126 that allows normal users to run commands as the root user.control-webpanel · webpanel · CWE-78 | Высокая8,8 | — | 19,8 % | 7 июл. 2022 г. |
41В плане | CVE-2020-15611Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Критическая9,8 | — | 8,3 % | 28 июл. 2020 г. |
41В плане | CVE-2020-15420Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-el7-0.9.8.891.control-webpanel · webpanel · CWE-78 | Критическая9,8 | — | 8,1 % | 28 июл. 2020 г. |
41В плане | CVE-2020-15425Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Критическая9,8 | — | 8,1 % | 28 июл. 2020 г. |
41В плане | CVE-2020-15428Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Критическая9,8 | — | 8,1 % | 28 июл. 2020 г. |
41В плане | CVE-2020-15430Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Критическая9,8 | — | 8,1 % | 28 июл. 2020 г. |
41В плане | CVE-2020-15431Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Критическая9,8 | — | 8,1 % | 28 июл. 2020 г. |
41В плане | CVE-2020-15426Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Критическая9,8 | — | 8,1 % | 28 июл. 2020 г. |
- CVE-2022-4487799Срочно
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS comma
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %control-webpanel · webpanel5 янв. 2023 г.
- CVE-2025-4870396Срочно
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in t
КритическаяCVSS 9,0KEVГотовый эксплойтEPSS 100 %control-webpanel · webpanel19 сент. 2025 г.
- CVE-2021-4546760На этой неделе
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.ph
КритическаяCVSS 9,8Proof of conceptEPSS 71 %control-webpanel · webpanel26 дек. 2022 г.
- CVE-2022-2504656В плане
A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request.
КритическаяCVSS 9,8Эксплойта нетEPSS 57 %control-webpanel · webpanel7 июл. 2022 г.
- CVE-2021-4546656В плане
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to a
КритическаяCVSS 9,8Эксплойта нетEPSS 55 %control-webpanel · webpanel26 дек. 2022 г.
- CVE-2018-1832351В плане
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/index.php?module=fil
ВысокаяCVSS 7,5Proof of conceptEPSS 71 %control-webpanel · webpanel15 окт. 2018 г.
- CVE-2021-3132449В плане
The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution
КритическаяCVSS 9,8Proof of conceptEPSS 35 %control-webpanel · webpanel18 мая 2021 г.
- CVE-2019-1336046В плане
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging k
КритическаяCVSS 9,8Proof of conceptEPSS 24 %control-webpanel · webpanel16 июл. 2019 г.
- CVE-2020-1023044В плане
CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php t
КритическаяCVSS 9,8Proof of conceptEPSS 16 %control-webpanel · webpanel16 мар. 2020 г.
- CVE-2018-1832244В плане
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php service_start
КритическаяCVSS 9,8Proof of conceptEPSS 15 %control-webpanel · webpanel15 окт. 2018 г.
- CVE-2021-3131643В плане
The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.
КритическаяCVSS 9,8Proof of conceptEPSS 13 %control-webpanel · webpanel18 мая 2021 г.
- CVE-2020-1542942В плане
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %control-webpanel · webpanel28 июл. 2020 г.
- CVE-2020-1543542В плане
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %control-webpanel · webpanel28 июл. 2020 г.
- CVE-2020-1561242В плане
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %control-webpanel · webpanel28 июл. 2020 г.
- CVE-2020-1543442В плане
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %control-webpanel · webpanel28 июл. 2020 г.
- CVE-2020-1542242В плане
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %control-webpanel · webpanel28 июл. 2020 г.
- CVE-2020-1562342В плане
This vulnerability allows remote attackers to write arbitrary files on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %control-webpanel · webpanel28 июл. 2020 г.
- CVE-2022-2504841В плане
Command injection vulnerability in CWP v0.9.8.1126 that allows normal users to run commands as the root user.
ВысокаяCVSS 8,8Эксплойта нетEPSS 20 %control-webpanel · webpanel7 июл. 2022 г.
- CVE-2020-1561141В плане
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %control-webpanel · webpanel28 июл. 2020 г.
- CVE-2020-1542041В плане
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-el7-0.9.8.891.
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %control-webpanel · webpanel28 июл. 2020 г.
- CVE-2020-1542541В плане
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %control-webpanel · webpanel28 июл. 2020 г.
- CVE-2020-1542841В плане
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %control-webpanel · webpanel28 июл. 2020 г.
- CVE-2020-1543041В плане
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %control-webpanel · webpanel28 июл. 2020 г.
- CVE-2020-1543141В плане
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %control-webpanel · webpanel28 июл. 2020 г.
- CVE-2020-1542641В плане
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %control-webpanel · webpanel28 июл. 2020 г.