|
|||
Rule General Information |
---|
Release Date: | 2023-02-20 | |
Rule Name: | CentOS Web Panel Command Injection Vulnerability (CVE-2022-44877) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter. | |
Impact: | An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software. | |
Affected OS: | Windows, Linux, Others | |
Reference: | http://packetstormsecurity.com/files/170388/Control-Web-Panel-7-Remote-Code-Execution.html http://packetstormsecurity.com/files/170820/Control-Web-Panel-Unauthenticated-Remote-Command-Execution.html http://seclists.org/fulldisclosure/2023/Jan/1 https://gist.github.com/numanturle/c1e82c47f4cba24cff214e904c227386 |
|
Solutions |
---|
Refer to the announcement or patch by the vendor: https://control-webpanel.com/changelog |