CVE-2018-18322: OS Command Injection
Published Oct 15, 2018
·Updated
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php servicestart, servicerestart, servicefullstatus, or servicestop parameter.
Affected Software
1 affected component
Control-webpanel Webpanel=0.9.8.480
Event History
Oct 15, 2018
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18322?
CVE-2018-18322 is classified as a high severity vulnerability due to its potential for command injection.
2
How do I fix CVE-2018-18322?
To fix CVE-2018-18322, you should update CentOS Web Panel to the latest version that addresses the command injection issue.
3
What systems are affected by CVE-2018-18322?
CVE-2018-18322 specifically affects CentOS Web Panel version 0.9.8.480.
4
What type of vulnerability is CVE-2018-18322?
CVE-2018-18322 is a command injection vulnerability that allows attackers to execute arbitrary commands on the server.
5
Can CVE-2018-18322 be exploited remotely?
Yes, CVE-2018-18322 can be exploited remotely if the attacker has access to the vulnerable service parameters.