Professional Webmasters Community
Would you like to react to this message? Create an account in a few clicks or log in to continue.

Cpanel File Manager XSS Vulnerability

Go down

Cpanel File Manager XSS Vulnerability Empty Cpanel File Manager XSS Vulnerability

Post  andry Wed Nov 03, 2010 1:52 am

Cpanel (www.cpanel.net) has two file manager application, standard and legacy one to manage files. Both of them are vulnerable to XSS attack. File name is presented unescaped so that an attacker can craft malicious file name to execute script on behalf of victims.

Version

-----------

this vulnerability was found on cpanel version 11.24.4-CURRENT

exploit here is already tested on: Firefox 3.0.7 and IE 8.0

Details
andry
andry
Moderator
Moderator

Posts : 467
Join date : 2010-05-07

Back to top Go down

Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum