CVE-2014-125123

Kloxo < 6.1.12 Unauthenticated SQL Injection RCE

Basic Information

CVE State
PUBLISHED
Reserved Date
July 30, 2025
Published Date
July 31, 2025
Last Updated
May 15, 2026
Vendor
LXCenter
Product
Kloxo
Description
An unauthenticated SQL injection vulnerability exists in the Kloxo web hosting control panel (developed by LXCenter) prior to version 6.1.12. The flaw resides in the login-name parameter passed to lbin/webcommand.php, which fails to properly sanitize input, allowing an attacker to extract the administrator’s password from the backend database. After recovering valid credentials, the attacker can authenticate to the Kloxo control panel and leverage the Command Center feature (display.php) to execute arbitrary operating system commands as root on the underlying host system. This vulnerability was reported to be exploited in the wild in January 2014.

CVSS Scores

CVSS v4.0

10.0 - CRITICAL

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

SSVC Information

Exploitation
poc
Automatable
Yes
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2026-06-01 10:38:09 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CVE 2026-06-01 10:38:09 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel