PT-2005-2834 · Lpanel · Lpanel
Published
2005-06-06
·
Updated
2008-09-05
·
CVE-2005-1877
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Lpanel versions 1.59 and earlier
Description
A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML and obtain sensitive information via the
pid parameter in the "view ticket.php" file.Recommendations
For Lpanel versions 1.59 and earlier, avoid using the
pid parameter in the view ticket.php file until a fix is available. As a temporary workaround, consider restricting access to the view ticket.php file to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lpanel