cPanel Unspecified Cross Site Scripting Vulnerability
BID:41723
Info
cPanel Unspecified Cross Site Scripting Vulnerability
| Bugtraq ID: | 41723 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 14 2010 12:00AM |
| Updated: | Jul 14 2010 12:00AM |
| Credit: | [email protected] |
| Vulnerable: |
cPanel cPanel 11.25 |
| Not Vulnerable: | |
Discussion
cPanel Unspecified Cross Site Scripting Vulnerability
cPanel is prone to an unspecified cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
cPanel 11.25 is vulnerable; other versions may also be affected.
cPanel is prone to an unspecified cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
cPanel 11.25 is vulnerable; other versions may also be affected.
Exploit / POC
cPanel Unspecified Cross Site Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
cPanel Unspecified Cross Site Scripting Vulnerability
Solution:
Reports indicate that updates are available; Symantec has not verified this. Please see the references for more information.
Solution:
Reports indicate that updates are available; Symantec has not verified this. Please see the references for more information.
References
cPanel Unspecified Cross Site Scripting Vulnerability
References:
References: