Vulnerabilities > CVE-2019-13386 - Incorrect Authorization vulnerability in Centos-Webpanel Centos web Panel 0.9.8.846

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
centos-webpanel
CWE-863

Summary

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, a hidden action=9 feature in filemanager2.php allows attackers to execute a shell command, i.e., obtain a reverse shell with user privilege.

Vulnerable Configurations

Part Description Count
Application
Centos-Webpanel
1

Common Weakness Enumeration (CWE)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/153876/cwp098836-exec.txt
idPACKETSTORM:153876
last seen2019-09-05
published2019-08-05
reporterPongtorn Angsuchotmetee
sourcehttps://packetstormsecurity.com/files/153876/CentOS-WebPanel.com-Control-Web-Panel-0.9.8.836-Remote-Command-Execution.html
titleCentOS-WebPanel.com Control Web Panel 0.9.8.836 Remote Command Execution