vendor:
CentOS Web Panel
by:
Berke YILMAZ
9.8
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: CentOS Web Panel
Affected Version From: v6
Affected Version To: v7
Patch Exists: YES
Related CWE: CVE-2020-10230
CPE: a:centos_webpanel:centos_webpanel
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali Linux, Windows 10
2020
Centos WebPanel 7 – ‘term’ SQL Injection
Centos WebPanel (http://centos-webpanel.com/) is a free Linux web hosting control panel designed for quick and easy management of (Dedicated & VPS) servers without of need to use ssh console for every little thing. This vulnerability allows an attacker to inject malicious SQL queries into the 'term' parameter of the 'loader_ajax.php' script, which can be used to extract sensitive information from the database or to execute arbitrary code on the server. The payloads used for exploiting this vulnerability are an Error Based SQL Injection and a Time Based SQL Injection.
Mitigation:
The vendor has released a patch to address this vulnerability. It is recommended to update to the latest version of Centos WebPanel.