PT-2018-14405 · Centos · Centos Web Panel

CVE-2018-18322

·

Publicado

2018-10-15

·

Atualizado

2023-01-24

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CentOS Web Panel version 0.9.8.480
Description The issue concerns Command Injection via shell metacharacters in the admin/index.php API endpoint, specifically in the service start, service restart, service fullstatus, or service stop parameters. This allows for potential command injection attacks.
Recommendations For version 0.9.8.480, consider disabling the service start, service restart, service fullstatus, and service stop parameters in the admin/index.php endpoint until a patch is available. Restrict access to the admin/index.php endpoint to minimize the risk of exploitation. Avoid using the service start, service restart, service fullstatus, and service stop parameters in the affected API endpoint until the issue is resolved.

Exploit

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-18322

Produtos afetados

Centos Web Panel