PT-2006-6550 · Cpanel · Cpanel

Published

2006-11-14

·

Updated

2018-10-17

·

CVE-2006-5883

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions cPanel version 10
Description The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote authenticated users to inject arbitrary web script or HTML. The affected parameters include the dir parameter in the "seldir.html" endpoint, and the user and dir parameters in the "newuser.html" endpoint.
Recommendations For cPanel version 10, update to a version that includes a fix for these XSS vulnerabilities to prevent remote authenticated users from injecting arbitrary web script or HTML. As a temporary workaround, consider restricting access to the "seldir.html" and "newuser.html" endpoints until a patch is available. Avoid using the dir, user parameters in these endpoints until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-5883

Affected Products

Cpanel