packetstormsecurity.com
http://packetstormsecurity.com/files/150169/CentOS-Web-Panel-0.9.8.740-Root-Account-Takeover-Command-Execution.html CVE-2018-18772
HIGH
CentOS Web Panel 0.9.8.740 - Cross-Site Request Forgery / Cross-Site Scripting
Record summary
CVE-2018-18772 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as demonstrated by executing an arbitrary OS command.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCentOS Web Panel 0.9.8.740 - Cross-Site Request Forgery / Cross-Site ScriptingExploitDB exploitby InfinitumITNot analyzed1 file
References
4packetstormsecurity.com
http://packetstormsecurity.com/files/150169/CentOS-Web-Panel-0.9.8.740-XSS-CSRF-Code-Execution.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-18772 45822exploit
https://www.exploit-db.com/exploits/45822