Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-2070

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2008-2070
Last Modified 07 Mar 2011 10:08:39
Published 12 May 2008 12:20:00
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2008-2070

Summary

The WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allows remote attackers to bypass XSS protection and inject arbitrary script or HTML via repeated, improperly-ordered "<" and ">" characters in the (1) issue parameter to scripts2/knowlegebase, (2) user parameter to scripts2/changeip, (3) search parameter to scripts2/listaccts, and other unspecified vectors.

Vulnerable Systems

Application

  • Cpanel 11.18

  • Cpanel 11.18.1

  • Cpanel 11.18.2

  • Cpanel 11.18.3

  • Cpanel 11.22

  • Cpanel 11.22.1

  • Cpanel 11.22.2


References

XF - cpanel-whminterface-xss(42305)

VUPEN - ADV-2008-1522

BID - 29125

BUGTRAQ - 20080509 XSS and CSRF vulnerability on Cpanel 11

SREASON - 3866

MISC - http://changelog.cpanel.net/?revision=0;tree=;treeview=;show=html;pp=25;te=1314;pg=2

SECUNIA - 30166

FULLDISC - 20080509 XSS and CSRF vulnerability on cPanel 11


Last Updated: 27 May 2016 10:47:45