CPanel Admin Interface HTML Injection Vulnerability
BID:8119
Info
CPanel Admin Interface HTML Injection Vulnerability
| Bugtraq ID: | 8119 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 07 2003 12:00AM |
| Updated: | Jul 07 2003 12:00AM |
| Credit: | Discovery of this issue is credited to Ory Segal <[email protected]>. |
| Vulnerable: |
cPanel cPanel 6.4.2 .STABLE_48 cPanel cPanel 6.4.2 cPanel cPanel 6.4.1 cPanel cPanel 6.4 cPanel cPanel 6.2 cPanel cPanel 6.0 cPanel cPanel 5.3 cPanel cPanel 5.0 |
| Not Vulnerable: |
cPanel cPanel 7.0 |
Discussion
CPanel Admin Interface HTML Injection Vulnerability
cPanel is prone to an HTML injection vulnerability. It is possible for remote attacks to include hostile HTML and script code in requests to cPanel, which will be logged. When logs are viewed by an administrative user, the injected code could be rendered in their browser in the context of the site hosting cPanel.
cPanel is prone to an HTML injection vulnerability. It is possible for remote attacks to include hostile HTML and script code in requests to cPanel, which will be logged. When logs are viewed by an administrative user, the injected code could be rendered in their browser in the context of the site hosting cPanel.
References
CPanel Admin Interface HTML Injection Vulnerability
References:
References:
- cPanel Homepage (cPanel)
- cPanel Malicious HTML Tags Injection Vulnerability (Ory Segal
)