HTTP: cPanel Multiple Module Cross-Site Scripting

This signature detects attempts to exploit a known cross-site scripting vulnerability in cPanel. It is due to insufficient validation of user-supplied input. Attackers can steal cookie-based authentication credentials and launch other attacks.

Extended Description

Multiple cross-site scripting vulnerabilities have been identified in cPanel that may allow an attacker to execute arbitrary HTML or script code in a user's browser. These issues exist due to a failure of the application to properly validate user-supplied URI input. The issues are reported to affect the 'account', 'db', 'login', 'email', 'dir', 'dns' and 'ip' parameters of 'ignorelist.html', 'showlog.html', 'repairdb.html', 'doaddftp.html', 'editmsg.html', 'testfile.html', 'erredit.html', 'dnslook.html', 'del.html' and 'index.html' scripts. The issues have been reported to affect version 9.1.0-R85 of the software, it is quite likely however that these issues affect previous versions of the software as well.

Affected Products

Cpanel cpanel

References

BugTraq: 10002 21142

CVE: CVE-2004-1875

Short Name
HTTP:XSS:CPANEL-MODULES
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2004-1875 Cross-Site Module Multiple Scripting bid:10002 bid:21142 cPanel
Release Date
04/26/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Cpanel

CVSS Score

9.3

Found a potential security threat?