Vulnerabilities > Control Webpanel > Webpanel > 0.9.8.480
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-10-15 | CVE-2018-18323 | Path Traversal vulnerability in Control-Webpanel Webpanel 0.9.8.480 CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/index.php?module=file_editor&file=/../ URI. | 7.5 |
2018-10-15 | CVE-2018-18322 | OS Command Injection vulnerability in Control-Webpanel Webpanel 0.9.8.480 CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php service_start, service_restart, service_fullstatus, or service_stop parameter. | 9.8 |