PT-2007-2332 · Cpanel · Cpanel Webhost Manager
Publicado
2007-02-12
·
Atualizado
2018-10-16
·
CVE-2007-0890
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
cPanel WebHost Manager (WHM) versions 11.0.0 and earlier
Description:
A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML. This is achieved via the
password parameter in scripts/passwdmysql.Recommendations:
For versions 11.0.0 and earlier, update to a version later than 11.0.0 to resolve the issue. As a temporary workaround, consider restricting access to the scripts/passwdmysql script to minimize the risk of exploitation. Avoid using the
password parameter in the affected script until the issue is resolved.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cpanel Webhost Manager