SQL injection vulnerability in ZPanel 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter to index.php or (2) page parameter to zpanel.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Zpanel | Zpanel | 2.0 (including) | 2.0 (including) |
Zpanel | Zpanel | 2.5_beta (including) | 2.5_beta (including) |
Zpanel | Zpanel | 2.5_beta9 (including) | 2.5_beta9 (including) |
Zpanel | Zpanel | 2.5_beta10 (including) | 2.5_beta10 (including) |