ZPanel Multiple Remote Security Vulnerabilities
BID:56400
CVE-2012-5686 |Info
ZPanel Multiple Remote Security Vulnerabilities
| Bugtraq ID: | 56400 |
| Class: | Unknown |
| CVE: |
CVE-2012-5683 CVE-2012-5684 CVE-2012-5685 CVE-2012-5686 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 05 2012 12:00AM |
| Updated: | Nov 05 2012 12:00AM |
| Credit: | pcsjj |
| Vulnerable: |
ZPanel ZPanel 10.0.1 |
| Not Vulnerable: | |
Discussion
ZPanel Multiple Remote Security Vulnerabilities
ZPanel is prone to multiple remote security vulnerabilities, including:
1. A cross-site request forgery vulnerability.
2. An HTML-injection vulnerability.
3. An SQL-injection vulnerability.
4. A security-bypass weakness.
Attackers can exploit these issues to bypass certain security restrictions, execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, to perform certain unauthorized actions, access or modify data, and exploit latent vulnerabilities in the underlying database. Other attacks may also be possible.
ZPanel is prone to multiple remote security vulnerabilities, including:
1. A cross-site request forgery vulnerability.
2. An HTML-injection vulnerability.
3. An SQL-injection vulnerability.
4. A security-bypass weakness.
Attackers can exploit these issues to bypass certain security restrictions, execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, to perform certain unauthorized actions, access or modify data, and exploit latent vulnerabilities in the underlying database. Other attacks may also be possible.