标题:Control Web Panel 操作系统命令注入漏洞
(CVE-2025-67888) Description:Control Web Panel是一款Linux虚拟主机控制面板。 Control Web Panel 0.9.8.1209之前版本存在操作系统命令注入漏洞,该漏洞源于对/admin/index.php中key参数清理不当,可能导致未经身份验证的攻击者注入并执行任意OS命令,从而获得root权限。
Description
Control Web Panel <= 0.9.8.1208 (admin/index.php) OS Command Injection Vulnerability • Software Link: