mirror of
https://github.com/0xMarcio/cve.git
synced 2025-12-18 20:48:19 +00:00
18 lines
775 B
Markdown
18 lines
775 B
Markdown
|
|
### [CVE-2019-13385](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13385)
|
||
|
|

|
||
|
|

|
||
|
|

|
||
|
|
|
||
|
|
### Description
|
||
|
|
|
||
|
|
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.840, File and Directory Information Exposure in filemanager allows attackers to enumerate users and check for active users of the application by reading /tmp/login.log.
|
||
|
|
|
||
|
|
### POC
|
||
|
|
|
||
|
|
#### Reference
|
||
|
|
- http://packetstormsecurity.com/files/153877/CentOS-Control-Web-Panel-0.9.8.840-User-Enumeration.html
|
||
|
|
|
||
|
|
#### Github
|
||
|
|
- https://github.com/i3umi3iei3ii/CentOS-Control-Web-Panel-CVE
|
||
|
|
|