PT-2008-3935 · Cpanel · Cpanel
CVE-2008-2478
·
Publicado
2008-05-28
·
Atualizado
2024-08-07
CVSS v2.0
8.5
Alta
| Vetor | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
cPanel versions 11.18.6 and earlier, 11.23.1 and earlier
Description:
The issue allows remote authenticated users with reseller privileges to execute arbitrary code via shell metacharacters in the
Email address field. The vendor disputes this issue, stating they are unable to reproduce it on multiple servers running different versions of cPanel.Recommendations:
For cPanel versions 11.18.6 and earlier, and 11.23.1 and earlier, consider restricting access to the
scripts/wwwacct functionality to minimize the risk of exploitation until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cpanel