BugTraq
CPANEL Vuln : HTML injection Jun 04 2004 03:46AM
qbann targ (web atomicrealms com)


Cpanel Resellers just can use an exploit in

the /scripts/killacct to delete one of my other customers accounts(only the

DNS info) not owned by him. All he had to do was create a fake account then

delete it and look at the source code, view his cookies and

discovered :2086/scripts/killacct?domain=(domain)&user=(user)&submit-

domain=Terminate . He ran it in his WHM with another of my customers domain

and username and it deleted his name server entries. And of course his site

won't show up anymore of course because of the dns info deleted. This would

seem like a pretty serious error, correct me if I am wrong, but I think this

issue should be addressed.

Discovered by : verb0s

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus