Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-2071

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2008-2071
Last Modified 07 Mar 2011 10:08:39
Published 12 May 2008 12:20:00
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2008-2071

Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in the WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allow remote attackers to perform unauthorized actions as cPanel administrators via requests to cpanel/whm/webmail and other unspecified vectors.

Vulnerable Systems

Application

  • Cpanel 11.18

  • Cpanel 11.18.1

  • Cpanel 11.18.2

  • Cpanel 11.18.3

  • Cpanel 11.22

  • Cpanel 11.22.1

  • Cpanel 11.22.2


References

XF - cpanel-whminterface-csrf(42306)

VUPEN - ADV-2008-1522

BID - 29125

BUGTRAQ - 20080509 XSS and CSRF vulnerability on Cpanel 11

SREASON - 3866

CONFIRM - http://changelog.cpanel.net/?revision=0;tree=;treeview=;show=html;pp=25;te=1314;pg=2

SECUNIA - 30166

FULLDISC - 20080509 XSS and CSRF vulnerability on cPanel 11


Last Updated: 27 May 2016 10:47:45