The following CentOS Web Panel is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible since a vulnerability allow remote attackers to achieve RCE (Remote code execution) on the service. Those vulnerabilities are currently used in ransomware campaign and could damage your network.
Reference:
Severity: critical
Fingerprint: b200c4085dcca515084ebea24b907d604b907d604b907d604b907d604b907d60
Found outdated CentOS Web Panel vulnerable to RCE Found CVE-2022-44877
The following CentOS Web Panel is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible since a vulnerability allow remote attackers to achieve RCE (Remote code execution) on the service. Those vulnerabilities are currently used in ransomware campaign and could damage your network.
Reference:
Severity: critical
Fingerprint: b200c4085dcca515084ebea24b907d604b907d604b907d604b907d604b907d60
Found outdated CentOS Web Panel vulnerable to RCE Found CVE-2022-44877
Open service 159.148.49.108:443 · www.barikades.lv
2024-12-22 04:26
HTTP/1.1 200 OK Date: Sun, 22 Dec 2024 04:26:05 GMT Server: CentOS WebPanel: Protected by Mod Security X-Powered-By: PHP/7.4.1 Link: <https://barikades.lv/wp-json/>; rel="https://api.w.org/", <https://barikades.lv/wp-json/wp/v2/pages/680>; rel="alternate"; type="application/json", <https://barikades.lv/>; rel=shortlink Vary: Accept-Encoding,User-Agent Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 159.148.49.108:443 · ledbaltic.com
2024-12-20 22:23
HTTP/1.1 200 OK Date: Fri, 20 Dec 2024 22:23:15 GMT Server: CentOS WebPanel: Protected by Mod Security X-Powered-By: PHP/7.4.1 Link: <https://ledbaltic.com/index.php/wp-json/>; rel="https://api.w.org/", <https://ledbaltic.com/index.php/wp-json/wp/v2/pages/13>; rel="alternate"; title="JSON"; type="application/json", <https://ledbaltic.com/>; rel=shortlink Vary: Accept-Encoding,User-Agent Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 159.148.49.108:443 · barikades.lv
2024-12-20 15:35
HTTP/1.1 200 OK Date: Fri, 20 Dec 2024 15:35:34 GMT Server: CentOS WebPanel: Protected by Mod Security X-Powered-By: PHP/7.4.1 Link: <https://barikades.lv/wp-json/>; rel="https://api.w.org/", <https://barikades.lv/wp-json/wp/v2/pages/680>; rel="alternate"; type="application/json", <https://barikades.lv/>; rel=shortlink Vary: Accept-Encoding,User-Agent Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 159.148.49.108:443 · www.barikades.lv
2024-12-20 07:41
HTTP/1.1 200 OK Date: Fri, 20 Dec 2024 07:41:14 GMT Server: CentOS WebPanel: Protected by Mod Security X-Powered-By: PHP/7.4.1 Link: <https://barikades.lv/wp-json/>; rel="https://api.w.org/", <https://barikades.lv/wp-json/wp/v2/pages/680>; rel="alternate"; type="application/json", <https://barikades.lv/>; rel=shortlink Vary: Accept-Encoding,User-Agent Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 159.148.49.108:443 · ledbaltic.com
2024-12-19 00:14
HTTP/1.1 200 OK Date: Thu, 19 Dec 2024 00:14:05 GMT Server: CentOS WebPanel: Protected by Mod Security X-Powered-By: PHP/7.4.1 Link: <https://ledbaltic.com/index.php/wp-json/>; rel="https://api.w.org/", <https://ledbaltic.com/index.php/wp-json/wp/v2/pages/13>; rel="alternate"; title="JSON"; type="application/json", <https://ledbaltic.com/>; rel=shortlink Vary: Accept-Encoding,User-Agent Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 159.148.49.108:443 · barikades.lv
2024-12-19 00:01
HTTP/1.1 200 OK Date: Thu, 19 Dec 2024 00:01:01 GMT Server: CentOS WebPanel: Protected by Mod Security X-Powered-By: PHP/7.4.1 Link: <https://barikades.lv/wp-json/>; rel="https://api.w.org/", <https://barikades.lv/wp-json/wp/v2/pages/680>; rel="alternate"; type="application/json", <https://barikades.lv/>; rel=shortlink Vary: Accept-Encoding,User-Agent Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 159.148.49.108:443 · www.barikades.lv
2024-12-18 06:36
HTTP/1.1 200 OK Date: Wed, 18 Dec 2024 06:36:28 GMT Server: CentOS WebPanel: Protected by Mod Security X-Powered-By: PHP/7.4.1 Link: <https://barikades.lv/wp-json/>; rel="https://api.w.org/", <https://barikades.lv/wp-json/wp/v2/pages/680>; rel="alternate"; type="application/json", <https://barikades.lv/>; rel=shortlink Vary: Accept-Encoding,User-Agent Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 159.148.49.108:443 · barikades.lv
2024-12-14 11:32
HTTP/1.1 200 OK Date: Sat, 14 Dec 2024 11:32:31 GMT Server: CentOS WebPanel: Protected by Mod Security X-Powered-By: PHP/7.4.1 Link: <https://barikades.lv/wp-json/>; rel="https://api.w.org/", <https://barikades.lv/wp-json/wp/v2/pages/680>; rel="alternate"; type="application/json", <https://barikades.lv/>; rel=shortlink Vary: Accept-Encoding,User-Agent Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 159.148.49.108:443 · www.barikades.lv
2024-12-14 10:46
HTTP/1.1 200 OK Date: Sat, 14 Dec 2024 10:46:32 GMT Server: CentOS WebPanel: Protected by Mod Security X-Powered-By: PHP/7.4.1 Link: <https://barikades.lv/wp-json/>; rel="https://api.w.org/", <https://barikades.lv/wp-json/wp/v2/pages/680>; rel="alternate"; type="application/json", <https://barikades.lv/>; rel=shortlink Vary: Accept-Encoding,User-Agent Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 159.148.49.108:443 · ledbaltic.com
2024-12-14 09:24
HTTP/1.1 200 OK Date: Sat, 14 Dec 2024 09:24:32 GMT Server: CentOS WebPanel: Protected by Mod Security X-Powered-By: PHP/7.4.1 Link: <https://ledbaltic.com/index.php/wp-json/>; rel="https://api.w.org/", <https://ledbaltic.com/index.php/wp-json/wp/v2/pages/13>; rel="alternate"; title="JSON"; type="application/json", <https://ledbaltic.com/>; rel=shortlink Vary: Accept-Encoding,User-Agent Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 159.148.49.108:443 · www.barikades.lv
2024-12-12 20:17
HTTP/1.1 200 OK Date: Thu, 12 Dec 2024 20:17:22 GMT Server: CentOS WebPanel: Protected by Mod Security X-Powered-By: PHP/7.4.1 Link: <https://barikades.lv/wp-json/>; rel="https://api.w.org/", <https://barikades.lv/wp-json/wp/v2/pages/680>; rel="alternate"; type="application/json", <https://barikades.lv/>; rel=shortlink Vary: Accept-Encoding,User-Agent Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 159.148.49.108:443 · barikades.lv
2024-12-12 16:42
HTTP/1.1 200 OK Date: Thu, 12 Dec 2024 16:42:14 GMT Server: CentOS WebPanel: Protected by Mod Security X-Powered-By: PHP/7.4.1 Link: <https://barikades.lv/wp-json/>; rel="https://api.w.org/", <https://barikades.lv/wp-json/wp/v2/pages/680>; rel="alternate"; type="application/json", <https://barikades.lv/>; rel=shortlink Vary: Accept-Encoding,User-Agent Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 159.148.49.108:443 · ledbaltic.com
2024-12-12 16:05
HTTP/1.1 400 Bad Request Date: Thu, 12 Dec 2024 16:05:13 GMT Server: CentOS WebPanel: Protected by Mod Security Content-Length: 362 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 400 Bad Request <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>400 Bad Request</title> </head><body> <h1>Bad Request</h1> <p>Your browser sent a request that this server could not understand.<br /> Reason: You're speaking plain HTTP to an SSL-enabled server port.<br /> Instead use the HTTPS scheme to access this URL, please.<br /> </p> </body></html>
Open service 159.148.49.108:443 · www.barikades.lv
2024-12-02 19:29
HTTP/1.1 200 OK Date: Mon, 02 Dec 2024 19:29:06 GMT Server: CentOS WebPanel: Protected by Mod Security X-Powered-By: PHP/7.4.1 Link: <https://barikades.lv/wp-json/>; rel="https://api.w.org/", <https://barikades.lv/wp-json/wp/v2/pages/680>; rel="alternate"; type="application/json", <https://barikades.lv/>; rel=shortlink Vary: Accept-Encoding,User-Agent Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 159.148.49.108:443 · ledbaltic.com
2024-12-02 15:36
HTTP/1.1 200 OK Date: Mon, 02 Dec 2024 15:36:29 GMT Server: CentOS WebPanel: Protected by Mod Security X-Powered-By: PHP/7.4.1 Link: <https://ledbaltic.com/index.php/wp-json/>; rel="https://api.w.org/", <https://ledbaltic.com/index.php/wp-json/wp/v2/pages/13>; rel="alternate"; title="JSON"; type="application/json", <https://ledbaltic.com/>; rel=shortlink Vary: Accept-Encoding,User-Agent Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 159.148.49.108:443 · barikades.lv
2024-12-02 13:09
HTTP/1.1 200 OK Date: Mon, 02 Dec 2024 13:09:29 GMT Server: CentOS WebPanel: Protected by Mod Security X-Powered-By: PHP/7.4.1 Link: <https://barikades.lv/wp-json/>; rel="https://api.w.org/", <https://barikades.lv/wp-json/wp/v2/pages/680>; rel="alternate"; type="application/json", <https://barikades.lv/>; rel=shortlink Vary: Accept-Encoding,User-Agent Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 159.148.49.108:443 · barikades.lv
2024-11-30 19:19
HTTP/1.1 200 OK Date: Sat, 30 Nov 2024 19:19:31 GMT Server: CentOS WebPanel: Protected by Mod Security X-Powered-By: PHP/7.4.1 Link: <https://barikades.lv/wp-json/>; rel="https://api.w.org/", <https://barikades.lv/wp-json/wp/v2/pages/680>; rel="alternate"; type="application/json", <https://barikades.lv/>; rel=shortlink Vary: Accept-Encoding,User-Agent Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 159.148.49.108:443 · www.barikades.lv
2024-11-30 16:36
HTTP/1.1 200 OK Date: Sat, 30 Nov 2024 16:36:37 GMT Server: CentOS WebPanel: Protected by Mod Security X-Powered-By: PHP/7.4.1 Link: <https://barikades.lv/wp-json/>; rel="https://api.w.org/", <https://barikades.lv/wp-json/wp/v2/pages/680>; rel="alternate"; type="application/json", <https://barikades.lv/>; rel=shortlink Vary: Accept-Encoding,User-Agent Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 159.148.49.108:443 · ledbaltic.com
2024-11-30 09:22
HTTP/1.1 200 OK Date: Sat, 30 Nov 2024 09:22:42 GMT Server: CentOS WebPanel: Protected by Mod Security X-Powered-By: PHP/7.4.1 Link: <https://ledbaltic.com/index.php/wp-json/>; rel="https://api.w.org/", <https://ledbaltic.com/index.php/wp-json/wp/v2/pages/13>; rel="alternate"; title="JSON"; type="application/json", <https://ledbaltic.com/>; rel=shortlink Vary: Accept-Encoding,User-Agent Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 159.148.49.108:80 · ledbaltic.com
2024-11-30 06:46
HTTP/1.1 301 Moved Permanently Date: Sat, 30 Nov 2024 06:46:35 GMT Server: CentOS WebPanel: Protected by Mod Security X-Powered-By: PHP/7.4.1 X-Redirect-By: WordPress Location: https://ledbaltic.com/ Vary: User-Agent Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 159.148.49.108:443 · barikades.lv
2024-11-28 23:46
HTTP/1.1 200 OK Date: Thu, 28 Nov 2024 23:47:00 GMT Server: CentOS WebPanel: Protected by Mod Security X-Powered-By: PHP/7.4.1 Link: <https://barikades.lv/wp-json/>; rel="https://api.w.org/", <https://barikades.lv/wp-json/wp/v2/pages/680>; rel="alternate"; type="application/json", <https://barikades.lv/>; rel=shortlink Vary: Accept-Encoding,User-Agent Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 159.148.49.108:443 · www.barikades.lv
2024-11-28 15:34
HTTP/1.1 200 OK Date: Thu, 28 Nov 2024 15:34:03 GMT Server: CentOS WebPanel: Protected by Mod Security X-Powered-By: PHP/7.4.1 Link: <https://barikades.lv/wp-json/>; rel="https://api.w.org/", <https://barikades.lv/wp-json/wp/v2/pages/680>; rel="alternate"; type="application/json", <https://barikades.lv/>; rel=shortlink Vary: Accept-Encoding,User-Agent Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 159.148.49.108:443 · ledbaltic.com
2024-11-28 07:37
HTTP/1.1 200 OK Date: Thu, 28 Nov 2024 07:37:59 GMT Server: CentOS WebPanel: Protected by Mod Security X-Powered-By: PHP/7.4.1 Link: <https://ledbaltic.com/index.php/wp-json/>; rel="https://api.w.org/", <https://ledbaltic.com/index.php/wp-json/wp/v2/pages/13>; rel="alternate"; title="JSON"; type="application/json", <https://ledbaltic.com/>; rel=shortlink Vary: Accept-Encoding,User-Agent Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 159.148.49.108:443 · www.barikades.lv
2024-11-26 18:30
HTTP/1.1 200 OK Date: Tue, 26 Nov 2024 18:30:21 GMT Server: CentOS WebPanel: Protected by Mod Security X-Powered-By: PHP/7.4.1 Link: <https://barikades.lv/wp-json/>; rel="https://api.w.org/", <https://barikades.lv/wp-json/wp/v2/pages/680>; rel="alternate"; type="application/json", <https://barikades.lv/>; rel=shortlink Vary: Accept-Encoding,User-Agent Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 159.148.49.108:443 · www.barikades.lv
2024-11-21 03:00
HTTP/1.1 200 OK Date: Thu, 21 Nov 2024 03:00:32 GMT Server: CentOS WebPanel: Protected by Mod Security X-Powered-By: PHP/7.4.1 Link: <https://barikades.lv/wp-json/>; rel="https://api.w.org/", <https://barikades.lv/wp-json/wp/v2/pages/680>; rel="alternate"; type="application/json", <https://barikades.lv/>; rel=shortlink Vary: Accept-Encoding,User-Agent Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 159.148.49.108:443 · ledbaltic.com
2024-11-21 00:01
HTTP/1.1 200 OK Date: Thu, 21 Nov 2024 00:01:33 GMT Server: CentOS WebPanel: Protected by Mod Security X-Powered-By: PHP/7.4.1 Link: <https://ledbaltic.com/index.php/wp-json/>; rel="https://api.w.org/", <https://ledbaltic.com/index.php/wp-json/wp/v2/pages/13>; rel="alternate"; title="JSON"; type="application/json", <https://ledbaltic.com/>; rel=shortlink Vary: Accept-Encoding,User-Agent Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 159.148.49.108:443 · barikades.lv
2024-11-20 22:08
HTTP/1.1 200 OK Date: Wed, 20 Nov 2024 22:08:55 GMT Server: CentOS WebPanel: Protected by Mod Security X-Powered-By: PHP/7.4.1 Link: <https://barikades.lv/wp-json/>; rel="https://api.w.org/", <https://barikades.lv/wp-json/wp/v2/pages/680>; rel="alternate"; type="application/json", <https://barikades.lv/>; rel=shortlink Vary: Accept-Encoding,User-Agent Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8