Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Kloxo Web Hosting Control Panel SQL Injection Vulnerability Allowing Remote Code Execution

Vulnerability

A SQL injection vulnerability has been identified in the Kloxo web hosting control panel, specifically in versions prior to 6.1.12. The vulnerability allows unauthenticated attackers to exploit the login-name parameter in 'lbin/webcommand.php', bypassing input sanitation to extract the administrator's password from the database. Once the password is obtained, attackers can log into the Kloxo control panel and use the Command Center feature to execute arbitrary commands as root on the server.

Impact

Exploitation of this vulnerability allows for unauthorized SQL injection, leading to extraction of sensitive data such as administrator passwords, followed by unauthorized access to the Kloxo control panel and execution of commands with root privileges on the server.

Reproduction

The vulnerability can be reproduced by sending a crafted HTTP request to 'lbin/webcommand.php' with a SQL injection payload in the 'login-name' parameter. This payload should be designed to exploit the application's SQL query handling, such as by using 'UNION SELECT' to extract data from the database. After successfully injecting and retrieving the password, the 'display.php' can be used to execute commands on the server as root.

Remediation

Users are advised to update to Kloxo version 6.1.12 or later, where this vulnerability has been addressed.

Added: Jul 31, 2025, 4:48 PM
Updated: Jul 31, 2025, 4:48 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
8.3
remediation
0.0
relevance
0.3
threat
9.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.