Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2008-2070
StatusCandidate
DescriptionThe WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allows remote attackers to bypass XSS protection and inject arbitrary script or HTML via repeated, improperly-ordered "<" and ">" characters in the (1) issue parameter to scripts2/knowlegebase, (2) user parameter to scripts2/changeip, (3) search parameter to scripts2/listaccts, and other unspecified vectors.
PhaseAssigned (05.05.2008)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2070
ReferencesBID : 29125
 BUGTRAQ : 20080509 XSS and CSRF vulnerability on Cpanel 11
 MISC : http://changelog.cpanel.net/?revision=0;tree=;tree...
 XF : cpanel-whminterface-xss(42305)
SecurityVulns:Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod
 



Rating@Mail.ru