PT-2008-3935 · Cpanel · Cpanel

Published

2008-05-28

·

Updated

2024-08-07

·

CVE-2008-2478

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: cPanel versions 11.18.6 and earlier, 11.23.1 and earlier
Description: The issue allows remote authenticated users with reseller privileges to execute arbitrary code via shell metacharacters in the Email address field. The vendor disputes this issue, stating they are unable to reproduce it on multiple servers running different versions of cPanel.
Recommendations: For cPanel versions 11.18.6 and earlier, and 11.23.1 and earlier, consider restricting access to the scripts/wwwacct functionality to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2008-2478

Affected Products

Cpanel