PT-2006-6250 · Cpanel · Cpanel

Crackers_Child

·

Publicado

2006-10-26

·

Atualizado

2018-10-17

·

CVE-2006-5535

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions cPanel versions 10.8.0 through 10.9.0 R50
Description The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the theme parameter to the "/scripts/dosetmytheme" API endpoint or the template parameter to the "/scripts2/editzonetemplate" API endpoint.
Recommendations For cPanel versions 10.8.0 through 10.9.0 R50, as a temporary workaround, consider restricting access to the "/scripts/dosetmytheme" and "/scripts2/editzonetemplate" API endpoints until a patch is available. Avoid using the theme and template parameters in these endpoints until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-5535

Produtos afetados

Cpanel