CVE-2022-44877

CVSS V2 None CVSS V3 None
Description
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.
Overview
  • CVE ID
  • CVE-2022-44877
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Modified
  • Published Version
  • 2023-01-05T23:15:09
  • Last Modified Date
  • 2023-04-06T17:15:09
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:centos-webpanel:centos_web_panel:*:*:*:*:*:*:*:* 1 OR 0.9.8.1147
History
Created Old Value New Value Data Type Notes
2023-01-05 23:16:49 Added to TrackCVE
2023-01-06 00:26:32 2023-01-05T23:20:46 CVE Modified Date updated
2023-01-06 00:26:32 Received Awaiting Analysis Vulnerability Status updated
2023-01-06 17:16:48 2023-01-06T17:15:09 CVE Modified Date updated
2023-01-06 17:16:48 References updated
2023-01-09 15:17:19 2023-01-09T15:15:10 CVE Modified Date updated
2023-01-09 15:17:19 RESERVED An issue in the /login/index.php component of Centos Web Panel 7 before v0.9.8.1147 allows unauthenticated attackers to execute arbitrary system commands via crafted HTTP requests. login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter. Description updated
2023-01-09 16:19:21 2023-01-09T16:15:10 CVE Modified Date updated
2023-01-09 16:19:21 References updated
2023-01-10 18:20:21 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2023-01-10 19:16:27 Undergoing Analysis Awaiting Analysis Vulnerability Status updated
2023-01-12 05:16:04 2023-01-11T21:55:28 CVE Modified Date updated
2023-01-12 05:16:04 Awaiting Analysis Analyzed Vulnerability Status updated
2023-01-12 05:16:05 Weakness Enumeration new
2023-01-12 05:16:07 CPE Information updated
2023-01-24 19:14:05 2023-01-24T19:00:53 CVE Modified Date updated
2023-01-31 20:13:15 2023-01-31T19:15:09 CVE Modified Date updated
2023-01-31 20:13:15 Analyzed Modified Vulnerability Status updated
2023-01-31 20:13:15 References updated
2023-02-01 19:14:25 Modified Undergoing Analysis Vulnerability Status updated
2023-02-22 14:14:00 2023-02-22T14:00:35 CVE Modified Date updated
2023-02-22 14:14:00 Undergoing Analysis Analyzed Vulnerability Status updated
2023-04-06 20:12:32 2023-04-06T17:15:09 CVE Modified Date updated
2023-04-06 20:12:32 Analyzed Modified Vulnerability Status updated
2023-04-06 20:12:33 References updated