Show filters
156 Total Results
Displaying 91-100 of 156
Sort by:
Attacker Value
Unknown
CVE-2019-15330
Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The webp-express plugin before 0.14.11 for WordPress has insufficient protection against arbitrary file reading.
0
Attacker Value
Unknown
CVE-2019-13476
Disclosure Date: August 21, 2019 (last updated November 27, 2024)
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, XSS in the domain parameter allows a low-privilege user to achieve root access via the email list page.
0
Attacker Value
Unknown
CVE-2019-14245
Disclosure Date: August 21, 2019 (last updated November 27, 2024)
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete databases (such as oauthv2) from the server via an attacker account.
0
Attacker Value
Unknown
CVE-2019-14246
Disclosure Date: August 21, 2019 (last updated November 27, 2024)
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to discover phpMyAdmin passwords (of any user in /etc/passwd) via an attacker account.
0
Attacker Value
Unknown
CVE-2019-13599
Disclosure Date: August 21, 2019 (last updated November 27, 2024)
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.848, the Login process allows attackers to check whether a username is valid by comparing response times.
0
Attacker Value
Unknown
CVE-2019-13477
Disclosure Date: August 21, 2019 (last updated November 27, 2024)
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, CSRF in the forgot password function allows an attacker to change the password for the root account.
0
Attacker Value
Unknown
CVE-2019-13385
Disclosure Date: July 26, 2019 (last updated November 27, 2024)
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.840, File and Directory Information Exposure in filemanager allows attackers to enumerate users and check for active users of the application by reading /tmp/login.log.
0
Attacker Value
Unknown
CVE-2019-13387
Disclosure Date: July 26, 2019 (last updated November 27, 2024)
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, Reflected XSS in filemanager2.php (parameter fm_current_dir) allows attackers to steal a cookie or session, or redirect to a phishing website.
0
Attacker Value
Unknown
CVE-2019-13386
Disclosure Date: July 26, 2019 (last updated November 27, 2024)
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, a hidden action=9 feature in filemanager2.php allows attackers to execute a shell command, i.e., obtain a reverse shell with user privilege.
0
Attacker Value
Unknown
CVE-2019-13359
Disclosure Date: July 16, 2019 (last updated November 27, 2024)
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, a cwpsrv-xxx cookie allows a normal user to craft and upload a session file to the /tmp directory, and use it to become the root user.
0