0day.today
https://0day.today/exploit/31304 CVE-2018-18323
HIGHNuclei
Centos Web Panel 0.9.8.480 - Multiple Vulnerabilities
Record summary
CVE-2018-18323 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Proofs of concept
1Catalogued exploits
ExploitDBCentos Web Panel 0.9.8.480 - Multiple VulnerabilitiesExploitDB exploitby seccopsNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHCentos Web Panel 0.9.8.480 - Local File InclusionCVSS 7.5
Centos Web Panel version 0.9.8.480 suffers from local file inclusion vulnerabilities. Other vulnerabilities including cross-site scripting and remote code execution are also known to impact this version.
Impact
Successful exploitation of this vulnerability allows an attacker to read sensitive files on the server.
Remediation
Upgrade to a patched version of Centos Web Panel.
WeaknessesCWE-22
Authors0x_Akoko
Template tagscve2018cvecentoslfipacketstormcontrol-webpanelxssvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:control-webpanel:webpanel:0.9.8.480:*:*:*:*:*:*:*
Shodan: http.title:"login | control webpanel"
FOFA: title="login | control webpanel"
Google: intitle:"login | control webpanel"
https://packetstormsecurity.com/files/149795/Centos-Web-Panel-0.9.8.480-XSS-LFI-Code-Execution.html http://centos-webpanel.com/ https://seccops.com/centos-web-panel-0-9-8-480-multiple-vulnerabilities/ https://nvd.nist.gov/vuln/detail/CVE-2018-18323 https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-18323 seccops.com
https://seccops.com/centos-web-panel-0-9-8-480-multiple-vulnerabilities 45610exploit
https://www.exploit-db.com/exploits/45610