cPanel HTML Injection and Cross-Site Scripting Vulnerabilities
BID:33840
Info
cPanel HTML Injection and Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 33840 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 05 2008 12:00AM |
| Updated: | Feb 20 2009 06:47PM |
| Credit: | mckt |
| Vulnerable: |
cPanel cPanel 11.24.7 cPanel cPanel 11.24.4 cPanel cPanel 11 |
| Not Vulnerable: | |
Discussion
cPanel HTML Injection and Cross-Site Scripting Vulnerabilities
cPanel is prone to an HTML-injection vulnerability and a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage the issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials, control how the site is rendered to the user, or launch other attacks.
These issues affect cPanel 11.24.4 and 11.24.7 builds 34195 and prior.
cPanel is prone to an HTML-injection vulnerability and a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage the issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials, control how the site is rendered to the user, or launch other attacks.
These issues affect cPanel 11.24.4 and 11.24.7 builds 34195 and prior.
Exploit / POC
cPanel HTML Injection and Cross-Site Scripting Vulnerabilities
Attackers can exploit these issues through a browser. To exploit a cross-site scripting issue, attackers must entice an unsuspecting user to follow a malicious URI.
Attackers can exploit these issues through a browser. To exploit a cross-site scripting issue, attackers must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
cPanel HTML Injection and Cross-Site Scripting Vulnerabilities
Solution:
The issues have been addressed in the Current and Edge builds of cPanel 11.24.4 and 11.24.7 with build ID grater than 34195. Please see the references for more information.
Solution:
The issues have been addressed in the Current and Edge builds of cPanel 11.24.4 and 11.24.7 with build ID grater than 34195. Please see the references for more information.
References
cPanel HTML Injection and Cross-Site Scripting Vulnerabilities
References:
References:
- cPanel Homepage (cPanel)
- cPanel Root XSS (mckt)