PT-2006-6550 · Cpanel · Cpanel

Publicado

2006-11-14

·

Atualizado

2018-10-17

·

CVE-2006-5883

CVSS v2.0

3.5

Baixa

VetorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions cPanel version 10
Description The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote authenticated users to inject arbitrary web script or HTML. The affected parameters include the dir parameter in the "seldir.html" endpoint, and the user and dir parameters in the "newuser.html" endpoint.
Recommendations For cPanel version 10, update to a version that includes a fix for these XSS vulnerabilities to prevent remote authenticated users from injecting arbitrary web script or HTML. As a temporary workaround, consider restricting access to the "seldir.html" and "newuser.html" endpoints until a patch is available. Avoid using the dir, user parameters in these endpoints until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-5883

Produtos afetados

Cpanel