Логотип exploitDog
bind:CVE-2023-42123
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-42123

Количество 3

Количество 3

nvd логотип

CVE-2023-42123

почти 2 года назад

Control Web Panel mysql_manager Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Control Web Panel. Authentication is required to exploit this vulnerability. The specific flaw exists within the mysql_manager module. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-21080.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-vj52-239v-8h2j

почти 2 года назад

Control Web Panel mysql_manager Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Control Web Panel. Authentication is required to exploit this vulnerability. The specific flaw exists within the mysql_manager module. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-21080.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2023-06352

почти 3 года назад

Уязвимость модуля mysql_manager приложения для управления серверами Control Web Panel (CWP) (ранее CentOS Web Panel) и средства антивирусной защиты Avast Premium Security, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-42123

Control Web Panel mysql_manager Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Control Web Panel. Authentication is required to exploit this vulnerability. The specific flaw exists within the mysql_manager module. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-21080.

CVSS3: 8.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-vj52-239v-8h2j

Control Web Panel mysql_manager Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Control Web Panel. Authentication is required to exploit this vulnerability. The specific flaw exists within the mysql_manager module. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-21080.

CVSS3: 8.8
1%
Низкий
почти 2 года назад
fstec логотип
BDU:2023-06352

Уязвимость модуля mysql_manager приложения для управления серверами Control Web Panel (CWP) (ранее CentOS Web Panel) и средства антивирусной защиты Avast Premium Security, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

CVSS3: 8.8
1%
Низкий
почти 3 года назад

Уязвимостей на страницу