An unauthenticated SQL injection vulnerability exists in the Kloxo web hosting control panel (developed by LXCenter) prior to version 6.1.12. The flaw resides in the login-name parameter passed to lbin/webcommand.php, which fails to properly sanitize input, allowing an attacker to extract the administrator’s password from the backend database. After recovering valid credentials, the attacker can authenticate to the Kloxo control panel and leverage the Command Center feature (display.php) to execute arbitrary operating system commands as root on the underlying host system. This vulnerability was reported to be exploited in the wild in January 2014.
History

Thu, 31 Jul 2025 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Lxcenter
Lxcenter kloxo
Vendors & Products Lxcenter
Lxcenter kloxo

Thu, 31 Jul 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 31 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
Description An unauthenticated SQL injection vulnerability exists in the Kloxo web hosting control panel (developed by LXCenter) prior to version 6.1.12. The flaw resides in the login-name parameter passed to lbin/webcommand.php, which fails to properly sanitize input, allowing an attacker to extract the administrator’s password from the backend database. After recovering valid credentials, the attacker can authenticate to the Kloxo control panel and leverage the Command Center feature (display.php) to execute arbitrary operating system commands as root on the underlying host system. This vulnerability was reported to be exploited in the wild in January 2014.
Title Kloxo < 6.1.12 Unauthenticated SQL Injection RCE
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-07-31T18:48:20.064Z

Reserved: 2025-07-30T15:09:12.063Z

Link: CVE-2014-125123

cve-icon Vulnrichment

Updated: 2025-07-31T18:48:07.609Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-31T15:15:34.770

Modified: 2025-07-31T18:42:37.870

Link: CVE-2014-125123

cve-icon Redhat

No data.