login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 prior to 0.9.8.1147 allows remote malicious users to execute arbitrary OS commands via shell metacharacters in the login parameter.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
control-webpanel webpanel |