Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Numan Turle

#13218of 53,638
20Total CVSS
Vulnerabilities · 2
Critical
2
PT-2022-6101
10
2022-10-25
Unknown · Control Web Panel · CVE-2022-44877
**Name of the Vulnerable Software and Affected Versions** Control Web Panel versions prior to 0.9.8.1147 **Description** The issue is related to the login/index.php component in Control Web Panel, which allows remote attackers to execute arbitrary OS commands via shell metacharacters in the `login` parameter. This can be exploited by sending specially crafted HTTP requests. The vulnerability is under active exploit and has a high severity rating. **Recommendations** For Control Web Panel versions prior to 0.9.8.1147, update to version 0.9.8.1147 or later to resolve the issue. As a temporary workaround, consider restricting access to the login/index.php component until a patch is applied. Avoid using the `login` parameter in the affected API endpoint until the issue is resolved.
PT-2018-12808
10
2018-08-04
Nuuo · Nuuo Nvrmini · CVE-2018-14933
**Name of the Vulnerable Software and Affected Versions** NUUO NVRmini devices (affected versions not specified) **Description** The issue allows for remote command execution via shell metacharacters in the `uploaddir` parameter for a "writeuploaddir" command in the "upgrade handle.php" file on NUUO NVRmini devices. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.