Record summary

CVE-2018-18323 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/index.php?module=file_editor&file=/../ URI.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBCentos Web Panel 0.9.8.480 - Multiple VulnerabilitiesExploitDB exploitby seccopsNot analyzed1 file

linked to 3 vulnerabilities

ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHCentos Web Panel 0.9.8.480 - Local File InclusionCVSS 7.5

Centos Web Panel version 0.9.8.480 suffers from local file inclusion vulnerabilities. Other vulnerabilities including cross-site scripting and remote code execution are also known to impact this version.

Impact

Successful exploitation of this vulnerability allows an attacker to read sensitive files on the server.

Remediation

Upgrade to a patched version of Centos Web Panel.

WeaknessesCWE-22
Authors0x_Akoko
Template tagscve2018cvecentoslfipacketstormcontrol-webpanelxssvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:control-webpanel:webpanel:0.9.8.480:*:*:*:*:*:*:*
Shodan: http.title:"login | control webpanel"
FOFA: title="login | control webpanel"
Google: intitle:"login | control webpanel"

Source: ProjectDiscovery

References

4