control-webpanel kayıtları
control-webpanel üreticisine ait 85 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 2 · %2,4
- Silahlaştırılmış
- 2 · %2,4
- Pre-auth RCE
- 32
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- 29 gün
Tekrar eden sınıflar
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')33
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')14
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-639 Authorization Bypass Through User-Controlled Key5
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
85 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2022-44877Silahlaştırılmış | login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commacontrol-webpanel · webpanel · CWE-78 | Kritik9,8 | KEV | %100,0 | 5 Oca 2023 |
96Hemen | CVE-2025-48703Silahlaştırılmış | CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in tcontrol-webpanel · webpanel · CWE-78 | Kritik9,0 | KEV | %99,7 | 19 Eyl 2025 |
60Bu hafta | CVE-2021-45467Kavram kanıtı | In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.phcontrol-webpanel · webpanel · CWE-862 | Kritik9,8 | — | %70,7 | 26 Ara 2022 |
56Planlayın | CVE-2022-25046İstismar yok | A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request.control-webpanel · webpanel · CWE-22 | Kritik9,8 | — | %57,4 | 7 Tem 2022 |
56Planlayın | CVE-2021-45466İstismar yok | In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to acontrol-webpanel · webpanel · CWE-863 | Kritik9,8 | — | %55,3 | 26 Ara 2022 |
51Planlayın | CVE-2018-18323Kavram kanıtı | CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/index.php?module=filcontrol-webpanel · webpanel · CWE-22 | Yüksek7,5 | — | %70,7 | 15 Eki 2018 |
49Planlayın | CVE-2021-31324Kavram kanıtı | The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Executioncontrol-webpanel · webpanel · CWE-78 | Kritik9,8 | — | %34,6 | 18 May 2021 |
46Planlayın | CVE-2019-13360Kavram kanıtı | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging kcontrol-webpanel · webpanel · CWE-639 | Kritik9,8 | — | %24,5 | 16 Tem 2019 |
44Planlayın | CVE-2020-10230Kavram kanıtı | CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php tcontrol-webpanel · webpanel · CWE-89 | Kritik9,8 | — | %15,8 | 16 Mar 2020 |
44Planlayın | CVE-2018-18322Kavram kanıtı | CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php service_startcontrol-webpanel · webpanel · CWE-78 | Kritik9,8 | — | %15,1 | 15 Eki 2018 |
43Planlayın | CVE-2021-31316Kavram kanıtı | The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.control-webpanel · webpanel · CWE-89 | Kritik9,8 | — | %13,3 | 18 May 2021 |
42Planlayın | CVE-2020-15429İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Kritik9,8 | — | %8,4 | 28 Tem 2020 |
42Planlayın | CVE-2020-15435İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Kritik9,8 | — | %8,4 | 28 Tem 2020 |
42Planlayın | CVE-2020-15612İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Kritik9,8 | — | %8,4 | 28 Tem 2020 |
42Planlayın | CVE-2020-15434İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Kritik9,8 | — | %8,4 | 28 Tem 2020 |
42Planlayın | CVE-2020-15422İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Kritik9,8 | — | %8,4 | 28 Tem 2020 |
42Planlayın | CVE-2020-15623İstismar yok | This vulnerability allows remote attackers to write arbitrary files on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-749 | Kritik9,8 | — | %8,3 | 28 Tem 2020 |
41Planlayın | CVE-2022-25048İstismar yok | Command injection vulnerability in CWP v0.9.8.1126 that allows normal users to run commands as the root user.control-webpanel · webpanel · CWE-78 | Yüksek8,8 | — | %19,8 | 7 Tem 2022 |
41Planlayın | CVE-2020-15611İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Kritik9,8 | — | %8,3 | 28 Tem 2020 |
41Planlayın | CVE-2020-15420İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-el7-0.9.8.891.control-webpanel · webpanel · CWE-78 | Kritik9,8 | — | %8,1 | 28 Tem 2020 |
41Planlayın | CVE-2020-15425İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Kritik9,8 | — | %8,1 | 28 Tem 2020 |
41Planlayın | CVE-2020-15428İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Kritik9,8 | — | %8,1 | 28 Tem 2020 |
41Planlayın | CVE-2020-15430İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Kritik9,8 | — | %8,1 | 28 Tem 2020 |
41Planlayın | CVE-2020-15431İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Kritik9,8 | — | %8,1 | 28 Tem 2020 |
41Planlayın | CVE-2020-15426İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Kritik9,8 | — | %8,1 | 28 Tem 2020 |
- CVE-2022-4487799Hemen
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS comma
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100control-webpanel · webpanel5 Oca 2023
- CVE-2025-4870396Hemen
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in t
KritikCVSS 9,0KEVSilahlaştırılmışEPSS %100control-webpanel · webpanel19 Eyl 2025
- CVE-2021-4546760Bu hafta
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.ph
KritikCVSS 9,8Kavram kanıtıEPSS %71control-webpanel · webpanel26 Ara 2022
- CVE-2022-2504656Planlayın
A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request.
KritikCVSS 9,8İstismar yokEPSS %57control-webpanel · webpanel7 Tem 2022
- CVE-2021-4546656Planlayın
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to a
KritikCVSS 9,8İstismar yokEPSS %55control-webpanel · webpanel26 Ara 2022
- CVE-2018-1832351Planlayın
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/index.php?module=fil
YüksekCVSS 7,5Kavram kanıtıEPSS %71control-webpanel · webpanel15 Eki 2018
- CVE-2021-3132449Planlayın
The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution
KritikCVSS 9,8Kavram kanıtıEPSS %35control-webpanel · webpanel18 May 2021
- CVE-2019-1336046Planlayın
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging k
KritikCVSS 9,8Kavram kanıtıEPSS %24control-webpanel · webpanel16 Tem 2019
- CVE-2020-1023044Planlayın
CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php t
KritikCVSS 9,8Kavram kanıtıEPSS %16control-webpanel · webpanel16 Mar 2020
- CVE-2018-1832244Planlayın
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php service_start
KritikCVSS 9,8Kavram kanıtıEPSS %15control-webpanel · webpanel15 Eki 2018
- CVE-2021-3131643Planlayın
The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.
KritikCVSS 9,8Kavram kanıtıEPSS %13control-webpanel · webpanel18 May 2021
- CVE-2020-1542942Planlayın
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
KritikCVSS 9,8İstismar yokEPSS %8control-webpanel · webpanel28 Tem 2020
- CVE-2020-1543542Planlayın
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
KritikCVSS 9,8İstismar yokEPSS %8control-webpanel · webpanel28 Tem 2020
- CVE-2020-1561242Planlayın
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
KritikCVSS 9,8İstismar yokEPSS %8control-webpanel · webpanel28 Tem 2020
- CVE-2020-1543442Planlayın
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
KritikCVSS 9,8İstismar yokEPSS %8control-webpanel · webpanel28 Tem 2020
- CVE-2020-1542242Planlayın
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
KritikCVSS 9,8İstismar yokEPSS %8control-webpanel · webpanel28 Tem 2020
- CVE-2020-1562342Planlayın
This vulnerability allows remote attackers to write arbitrary files on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
KritikCVSS 9,8İstismar yokEPSS %8control-webpanel · webpanel28 Tem 2020
- CVE-2022-2504841Planlayın
Command injection vulnerability in CWP v0.9.8.1126 that allows normal users to run commands as the root user.
YüksekCVSS 8,8İstismar yokEPSS %20control-webpanel · webpanel7 Tem 2022
- CVE-2020-1561141Planlayın
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
KritikCVSS 9,8İstismar yokEPSS %8control-webpanel · webpanel28 Tem 2020
- CVE-2020-1542041Planlayın
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-el7-0.9.8.891.
KritikCVSS 9,8İstismar yokEPSS %8control-webpanel · webpanel28 Tem 2020
- CVE-2020-1542541Planlayın
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
KritikCVSS 9,8İstismar yokEPSS %8control-webpanel · webpanel28 Tem 2020
- CVE-2020-1542841Planlayın
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
KritikCVSS 9,8İstismar yokEPSS %8control-webpanel · webpanel28 Tem 2020
- CVE-2020-1543041Planlayın
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
KritikCVSS 9,8İstismar yokEPSS %8control-webpanel · webpanel28 Tem 2020
- CVE-2020-1543141Planlayın
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
KritikCVSS 9,8İstismar yokEPSS %8control-webpanel · webpanel28 Tem 2020
- CVE-2020-1542641Planlayın
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
KritikCVSS 9,8İstismar yokEPSS %8control-webpanel · webpanel28 Tem 2020