#VU29398 Command Injection in CentOS Web Panel - CVE-2020-15435
Published: June 30, 2020 / Updated: June 30, 2020
CentOS Web Panel
CentOS Web Panel
Description
The vulnerability allows a remote attacker to execute arbitrary commands on the system.
The vulnerability exists due to improper input validation in the "service_start" parameter in "ajax_dashboard.php". A remote attacker can send a specially crafted data and execute arbitrary commands on the target system.