← Back

Webpanel

webpanel

Vendor: Control Webpanel • 85 CVEs

CVEs (85)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Control Webpanel
1Webpanel
Nov 21, 2024
Sep 10, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to change the e-mail password of a victim account via an attacker account.
1Control Webpanel
1Webpanel
Nov 21, 2024
Sep 10, 2019
N/A· v4
5.4 MEDIUM· v3
6.5 MEDIUM· v2
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to access and delete DNS records of a victim's account via an attacker account.
1Control Webpanel
1Webpanel
Nov 21, 2024
Sep 10, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete a victim's e-mail account via an attacker account.
1Control Webpanel
1Webpanel
Nov 21, 2024
Sep 10, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete an e-mail forwarding destination from a victim's account via an attacker account.
1Control Webpanel
1Webpanel
Nov 21, 2024
Sep 10, 2019
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to remove a target user from phpMyAdmin via an attacker account.
1Control Webpanel
1Webpanel
Nov 21, 2024
Aug 21, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, XSS in the domain parameter allows a low-privilege user to achieve root access via the email list page.
1Control Webpanel
1Webpanel
Nov 21, 2024
Aug 21, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.848, the Login process allows attackers to check whether a username is valid by comparing response times.
1Control Webpanel
1Webpanel
Nov 21, 2024
Aug 21, 2019
N/A· v4
8.8 HIGH· v3
4.3 MEDIUM· v2
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, CSRF in the forgot password function allows an attacker to change the password for the root account.
1Control Webpanel
1Webpanel
Nov 21, 2024
Jul 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, Reflected XSS in filemanager2.php (parameter fm_current_dir) allows attackers to steal a cookie or session, or redirect to a phishing website.
1Control Webpanel
1Webpanel
Nov 21, 2024
Jul 26, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.840, File and Directory Information Exposure in filemanager allows attackers to enumerate users and check for active users of the application by reading /tmp/login....Show more
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.840, File and Directory Information Exposure in filemanager allows attackers to enumerate users and check for active users of the application by reading /tmp/login.log.Show less
1Control Webpanel
1Webpanel
Nov 21, 2024
Jul 16, 2019
N/A· v4
7.5 HIGH· v3
8.5 HIGH· v2
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, a cwpsrv-xxx cookie allows a normal user to craft and upload a session file to the /tmp directory, and use it to become the root user.
1Control Webpanel
1Webpanel
Nov 21, 2024
Jul 16, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote attackers can bypass authentication in the login process by leveraging the knowledge of a valid username. The attacker must defeat an encod...Show more
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote attackers can bypass authentication in the login process by leveraging the knowledge of a valid username. The attacker must defeat an encoding that is not equivalent to base64, and thus this is different from CVE-2019-13360.Show less
1Control Webpanel
1Webpanel
Nov 21, 2024
Jul 16, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, the Login process allows attackers to check whether a username is valid by reading the HTTP response.
1Control Webpanel
1Webpanel
Nov 21, 2024
Jul 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging knowledge of a valid username.
1Control Webpanel
1Webpanel
Nov 21, 2024
May 21, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
XSS was discovered in CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.747 via the testacc/fileManager2.php fm_current_dir or filename parameter.
1Control Webpanel
1Webpanel
Nov 21, 2024
May 13, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version), 0.9.8.753 (Pro) and 0.9.8.807 (Pro) is vulnerable to Reflected XSS for the "Domain" field on the "DNS Functions > "Add DNS Zone" screen...Show more
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version), 0.9.8.753 (Pro) and 0.9.8.807 (Pro) is vulnerable to Reflected XSS for the "Domain" field on the "DNS Functions > "Add DNS Zone" screen.Show less
1Control Webpanel
1Webpanel
Nov 21, 2024
Mar 26, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.763 is vulnerable to Stored/Persistent XSS for the "Package Name" field via the add_package module parameter.
1Control Webpanel
1Webpanel
Nov 21, 2024
Nov 20, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter.
1Control Webpanel
1Webpanel
Nov 21, 2024
Nov 20, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demonstrated by changing the root password.
1Control Webpanel
1Webpanel
Nov 21, 2024
Nov 20, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as demonstrated by executing an arbitrary OS command.