Git Product home page Git Product logo

centos-control-web-panel-cve's Introduction

CentOS Control Web Panel (version 0.9.8.836 - 0.9.8.847)

On June 29, 2019 our team started to find vulnerability on CentOS Control Web Panel (CWP) version 0.9.8.836, and we found some critical vulnerabilites. Some of the vulnerabilities we found can be chained to compromise the server from anonymous user to be root user. After our team reported to CWP, they responsed us quickly.

Finally, all of vulnerabilities are mentioned here have been fixed on CWP version 0.9.8.848 (CVE-2019-133xx) and version 0.9.8.866 (CVE-2019-142xx)


" This repository is purely intended for educational and research purposes only. We do NOT want anyone to use any information from this repository to attack or do illegal thing (refer to the laws in your country). So that, any actions and or activities related to the materials from this repository is solely your responsibility. If you don’t agree, you are not allowed to access this repository, leave this repository immediately "


Vulnerabilities List

CVE-2019-13359 - Root Privilege Escalation

CVE-2019-13360 - User panel bypass Login #1

CVE-2019-13605 - User panel bypass Login #2

CVE-2019-13383 - User Enumeration via HTTP response message

CVE-2019-13385 - Active User Enumeration via login.log

CVE-2019-13386 - Remote Command Execution

CVE-2019-13387 - Reflected Cross Site Scripting

CVE-2019-14245 - Arbitrary database dropping

CVE-2019-14246 - Reset other phpMyadmin password

CVE-2019-13599 - User enumerate through HTTP response time

CVE-2019-13476 - Cross Site Scripting (Stored) through New Mail Box

CVE-2019-13477 - CSRF through New Mail Box for change password user root

CVE-2019-XXXXX Coming soon...


The software is seperated to be 2 parts, root panel and user panel. If you try to install the old version by changing software version in the installation script, you will get install previous version of root panel but the user panel is only available for the lastest version (cannot specific version to download)


Discovered by

Pongtorn Angsuchotmetee
Nissana Sirijirakal
Narin Boonwasanarak

centos-control-web-panel-cve's People

Contributors

alasn0t avatar i3umi3iei3ii avatar tstckdg9 avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.