PT-2008-3935 · Cpanel · Cpanel
Published
2008-05-28
·
Updated
2024-08-07
·
CVE-2008-2478
CVSS v2.0
8.5
High
| Vector | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
cPanel versions 11.18.6 and earlier, 11.23.1 and earlier
Description:
The issue allows remote authenticated users with reseller privileges to execute arbitrary code via shell metacharacters in the
Email address field. The vendor disputes this issue, stating they are unable to reproduce it on multiple servers running different versions of cPanel.Recommendations:
For cPanel versions 11.18.6 and earlier, and 11.23.1 and earlier, consider restricting access to the
scripts/wwwacct functionality to minimize the risk of exploitation until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cpanel