cPanel Multiple Module Cross-Site...

- AV AC AU C I A
发布: 2004-03-30
修订: 2025-04-13

Multiple cross-site scripting vulnerabilities have been identified in cPanel that may allow an attacker to execute arbitrary HTML or script code in a user's browser. These issues exist due to a failure of the application to properly validate user-supplied URI input. The issues are reported to affect the 'account', 'db', 'login', 'email', 'dir', 'dns' and 'ip' parameters of 'ignorelist.html', 'showlog.html', 'repairdb.html', 'doaddftp.html', 'editmsg.html', 'testfile.html', 'erredit.html', 'dnslook.html', 'del.html' and 'index.html' scripts. The issues have been reported to affect version 9.1.0-R85 of the software, it is quite likely however that these issues affect previous versions of the software as well.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息