First published: Thu Jul 10 2003(Updated: )
Cross-site scripting (XSS) vulnerability in cPanel 6.4.2 allows remote attackers to insert arbitrary HTML and possibly gain cPanel administrator privileges via script in a URL that is logged but not properly quoted when displayed via the (1) Error Log or (2) Latest Visitors screens.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
cPanel | =5.0 | |
cPanel | =5.3 | |
cPanel | =6.0 | |
cPanel | =6.2 | |
cPanel | =6.4 | |
cPanel | =6.4.1 | |
cPanel | =6.4.2 | |
cPanel | =6.4.2_stable_48 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0521 has a high severity due to its potential to allow remote attackers to execute arbitrary HTML and gain cPanel administrator privileges.
To fix CVE-2003-0521, it is recommended to update cPanel to the latest version that addresses this vulnerability.
CVE-2003-0521 affects cPanel versions 5.0, 5.3, 6.0, 6.2, 6.4, and specifically 6.4.2.
Exploiting CVE-2003-0521 may allow attackers to inject malicious scripts leading to unauthorized access and potential control of the cPanel environment.
CVE-2003-0521 is an older vulnerability, but its relevance depends on whether vulnerable versions of cPanel are still in use.