List Info

Thread: PCWorks: cPanel Multiple Cross-Site Scripting Vulnerabilities




PCWorks: cPanel Multiple Cross-Site Scripting Vulnerabilities
user name
2006-10-31 04:37:36
I think this happened to me.
I went to my shopping cart main page and there was a Turkish
site there.
No damage seemed to be done.

Jeff
www.hdtvrepair.tv   www.intrepid-video.com

 

-----Original Message-----
From: owner-pcworksimagicomm.com [mailto:owner-pcworksimagicomm.com] On
Behalf Of Support-OrpheusComputing.com
Sent: Friday, October 27, 2006 5:25 AM
To: PCworksimagicomm.com
Subject: PCWorks: cPanel Multiple Cross-Site Scripting
Vulnerabilities

For those of you that have websites that use cPanel.
-Clint


----- Original Message ----- 

TITLE:
cPanel Multiple Cross-Site Scripting Vulnerabilities

SECUNIA ADVISORY ID:
SA22555

VERIFY ADVISORY:
http://secunia.c
om/advisories/22555/

CRITICAL:
Less critical

IMPACT:
Cross Site Scripting

WHERE:
From remote

SOFTWARE:
cPanel 10.x
http://secunia.com/p
roduct/5280/

DESCRIPTION:
Vulnerabilities in cPanel, which can be exploited by
malicious
people to conduct cross-site scripting attacks.

Input passed to the "theme" parameter in
scripts/dosetmytheme
and to the "template" parameter in
scripts2/editzonetemplate in
WebHost Manager is not properly sanitised before being
returned
to the user.  This can be exploited to execute arbitrary
HTML
and script code in an administrative user's browser session
in
context of an affected site.

The vulnerabilities are reported in version WHM 10.8.0
cPanel
10.9.0 R50.  Other versions may also be affected.
============= PCWorks Mailing List =================
Don't see your post? Check our posting guidelines &
make sure you've followed proper posting procedures,
http://pcworkers.com/r
ules.htm
Contact list owner <owner-pcworksimagicomm.com>
Unsubscribing and other changes: http://pcworkers.com
=====================================================
[1]

about | contact  Other archives ( Real Estate discussion Medical topics )