CPanel SCGIwrap Path Disclosure And Cross-Site Scripting Vulnerabilities
BID:24586
Info
CPanel SCGIwrap Path Disclosure And Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 24586 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3367 CVE-2007-3366 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 22 2007 12:00AM |
| Updated: | Jul 05 2016 10:00PM |
| Credit: | agentsteal is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
cPanel cPanel 11.0 cPanel cPanel 10.9 cPanel cPanel 10.8.2 118 cPanel cPanel 10.8.1 113 cPanel cPanel 10.8.1 (build 84) cPanel cPanel 10.6 .0-R137 cPanel cPanel 10.2 .0-R82 cPanel cPanel 9.9.1 -R3 cPanel cPanel 9.4.1 -R64 cPanel cPanel 9.1 .0-R85 cPanel cPanel 9.1 cPanel cPanel 9.0 cPanel cPanel 8.0 cPanel cPanel 7.0 cPanel cPanel 6.4.2 .STABLE_48 cPanel cPanel 6.4.2 cPanel cPanel 6.4.1 cPanel cPanel 6.4 cPanel cPanel 6.2 cPanel cPanel 6.0 cPanel cPanel 5.3 cPanel cPanel 5.0 cPanel cPanel 11 beta cPanel cPanel 11 |
| Not Vulnerable: |
cPanel cPanel 11.4.19 cPanel cPanel 10.9.1 |
Discussion
CPanel SCGIwrap Path Disclosure And Cross-Site Scripting Vulnerabilities
cPanel is prone to path-disclosure and cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and to access sensitive data that may be used to launch further attacks against a vulnerable computer.
These versions are affected:
- cPanel 311.4.19-R14378 in the RELEASE and CURRENT branches
- versions prior to cPanel 10.9.1 in the STABLE branch
cPanel is prone to path-disclosure and cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and to access sensitive data that may be used to launch further attacks against a vulnerable computer.
These versions are affected:
- cPanel 311.4.19-R14378 in the RELEASE and CURRENT branches
- versions prior to cPanel 10.9.1 in the STABLE branch
Exploit / POC
CPanel SCGIwrap Path Disclosure And Cross-Site Scripting Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
CPanel SCGIwrap Path Disclosure And Cross-Site Scripting Vulnerabilities
Solution:
The vendor released an update to address these issues. Please see the references for more information.
Solution:
The vendor released an update to address these issues. Please see the references for more information.
References
CPanel SCGIwrap Path Disclosure And Cross-Site Scripting Vulnerabilities
References:
References:
- cPanel Homepage (cPanel)