PT-2012-5038 · Jbmc · Directadmin
Dawid Golak
·
Published
2012-07-03
·
Updated
2025-12-05
·
CVE-2012-3842
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
JBMC Software DirectAdmin version 1.403
Description
The issue concerns multiple cross-site scripting (XSS) vulnerabilities in the CMD DOMAIN component. These vulnerabilities allow remote authenticated users with specific privileges to inject arbitrary web script or HTML. The injection can occur via the
select0 or select8 parameters.Recommendations
For version 1.403, consider restricting access to the CMD DOMAIN component until a patch is available. As a temporary workaround, avoid using the
select0 and select8 parameters in the affected API endpoint.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Directadmin