Show filters
156 Total Results
Displaying 31-40 of 156
Sort by:
Attacker Value
Unknown

CVE-2020-18664

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
Cross Site Scripting (XSS) vulnerability in WebPort <=1.19.1via the connection name parameter in type-conn.
Attacker Value
Unknown

CVE-2020-18665

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
Directory Traversal vulnerability in WebPort <=1.19.1 in tags of system settings.
Attacker Value
Unknown

CVE-2021-31316

Disclosure Date: May 18, 2021 (last updated February 22, 2025)
The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.
Attacker Value
Unknown

CVE-2021-31324

Disclosure Date: May 18, 2021 (last updated February 22, 2025)
The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.
Attacker Value
Unknown

CVE-2020-15262

Disclosure Date: October 19, 2020 (last updated February 22, 2025)
In webpack-subresource-integrity before version 1.5.1, all dynamically loaded chunks receive an invalid integrity hash that is ignored by the browser, and therefore the browser cannot validate their integrity. This removes the additional level of protection offered by SRI for such chunks. Top-level chunks are unaffected. This issue is patched in version 1.5.1.
Attacker Value
Unknown

CVE-2020-23659

Disclosure Date: August 26, 2020 (last updated February 22, 2025)
WebPort-v1.19.17121 is affected by Cross Site Scripting (XSS) on the "connections" feature.
Attacker Value
Unknown

CVE-2020-15624

Disclosure Date: July 28, 2020 (last updated February 21, 2025)
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_new_account.php. When parsing the domain parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose information in the context of root. Was ZDI-CAN-9727.
Attacker Value
Unknown

CVE-2020-15625

Disclosure Date: July 28, 2020 (last updated February 21, 2025)
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_add_mailbox.php. When parsing the username parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose information in the context of root. Was ZDI-CAN-9729.
Attacker Value
Unknown

CVE-2020-15430

Disclosure Date: July 28, 2020 (last updated February 21, 2025)
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_list_accounts.php. When parsing the username parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-9736.
Attacker Value
Unknown

CVE-2020-15610

Disclosure Date: July 28, 2020 (last updated February 21, 2025)
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_php_pecl.php. When parsing the modulo parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-9728.