Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:XSS:CPANEL-MODULES

Severity

Medium

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

cPanel Multiple Module Cross-Site Scripting

Release Date

2013/04/25

Update Number

2258

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: cPanel Multiple Module Cross-Site Scripting


This signature detects attempts to exploit a known cross-site scripting vulnerability in cPanel. It is due to insufficient validation of user-supplied input. Attackers can steal cookie-based authentication credentials and launch other attacks.

Extended Description

Multiple cross-site scripting vulnerabilities have been identified in cPanel that may allow an attacker to execute arbitrary HTML or script code in a user's browser. These issues exist due to a failure of the application to properly validate user-supplied URI input. The issues are reported to affect the 'account', 'db', 'login', 'email', 'dir', 'dns' and 'ip' parameters of 'ignorelist.html', 'showlog.html', 'repairdb.html', 'doaddftp.html', 'editmsg.html', 'testfile.html', 'erredit.html', 'dnslook.html', 'del.html' and 'index.html' scripts. The issues have been reported to affect version 9.1.0-R85 of the software, it is quite likely however that these issues affect previous versions of the software as well.

Affected Products

  • cPanel 9.1.0 .0-R85

References

  • BugTraq: 21142
  • BugTraq: 10002
  • CVE: CVE-2004-1875

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out