An unauthenticated SQL injection vulnerability exists in the Kloxo web hosting control panel (developed by LXCenter) prior to version 6.1.12. The flaw resides in the login-name parameter passed to lbin/webcommand.php, which fails to properly sanitize input, allowing an attacker to extract the administrator’s password from the backend database. After recovering valid credentials, the attacker can authenticate to the Kloxo control panel and leverage the Command Center feature (display.php) to execute arbitrary operating system commands as root on the underlying host system. This vulnerability was reported to be exploited in the wild in January 2014.
Metrics
Affected Vendors & Products
References
History
Thu, 31 Jul 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Lxcenter
Lxcenter kloxo |
|
Vendors & Products |
Lxcenter
Lxcenter kloxo |
Thu, 31 Jul 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 31 Jul 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An unauthenticated SQL injection vulnerability exists in the Kloxo web hosting control panel (developed by LXCenter) prior to version 6.1.12. The flaw resides in the login-name parameter passed to lbin/webcommand.php, which fails to properly sanitize input, allowing an attacker to extract the administrator’s password from the backend database. After recovering valid credentials, the attacker can authenticate to the Kloxo control panel and leverage the Command Center feature (display.php) to execute arbitrary operating system commands as root on the underlying host system. This vulnerability was reported to be exploited in the wild in January 2014. | |
Title | Kloxo < 6.1.12 Unauthenticated SQL Injection RCE | |
Weaknesses | CWE-89 | |
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-07-31T18:48:20.064Z
Reserved: 2025-07-30T15:09:12.063Z
Link: CVE-2014-125123

Updated: 2025-07-31T18:48:07.609Z

Status : Awaiting Analysis
Published: 2025-07-31T15:15:34.770
Modified: 2025-07-31T18:42:37.870
Link: CVE-2014-125123

No data.