seccops

6 exploits Active since Oct 2018
CVE-2025-14018 NOMISEC HIGH WRITEUP
NetBT Consulting Services Inc. E-Fatura <1.2.15 - Path Traversal
Unquoted Search Path or Element vulnerability in NetBT Consulting Services Inc. E-Fatura allows Leveraging/Manipulating Configuration File Search Paths, Redirect Access to Libraries.This issue affects e-Fatura: before 1.2.15.
CVSS 7.3
CVE-2025-14018 EXPLOITDB HIGH text
NetBT Consulting Services Inc. E-Fatura <1.2.15 - Path Traversal
Unquoted Search Path or Element vulnerability in NetBT Consulting Services Inc. E-Fatura allows Leveraging/Manipulating Configuration File Search Paths, Redirect Access to Libraries.This issue affects e-Fatura: before 1.2.15.
CVSS 7.3
CVE-2018-18323 EXPLOITDB HIGH text WORKING POC
Webpanel - Path Traversal
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/index.php?module=file_editor&file=/../ URI.
CVSS 7.5
CVE-2018-18322 EXPLOITDB CRITICAL text WORKING POC
Webpanel - OS Command Injection
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php service_start, service_restart, service_fullstatus, or service_stop parameter.
CVSS 9.8
CVE-2018-18075 EXPLOITDB CRITICAL text WORKING POC
Wikidforum - SQL Injection
WikidForum 2.20 has SQL Injection via the rpc.php parent_post_id or num_records parameter, or the index.php?action=search select_sort parameter.
CVSS 9.8
CVE-2018-18324 EXPLOITDB MEDIUM text WORKING POC
Webpanel - XSS
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has XSS via the admin/fileManager2.php fm_current_dir parameter, or the admin/index.php module, service_start, service_fullstatus, service_restart, service_stop, or file (within the file_editor) parameter.
CVSS 6.1