First published: Tue Feb 07 2006(Updated: )
Multiple cross-site scripting (XSS) vulnerabilies in cPanel 10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to (a) editquota.html or (b) dodelpop.html; (2) showtree parameter to (c) diskusage.html; or the (3) mon, (4) year, (5) target, or (6) domain parameter to (d) stats/detailbw.html.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cpanel Cpanel | =9.0 | |
Cpanel Cpanel | =6.4 | |
Cpanel Cpanel | =5.3 | |
Cpanel Cpanel | =5.0 | |
Cpanel Cpanel | =6.0 | |
Cpanel Cpanel | =6.4.1 | |
Cpanel Cpanel | =6.4.2_stable_48 | |
Cpanel Cpanel | =6.4.2 | |
Cpanel Cpanel | =8.0 | |
Cpanel Cpanel | =9.1 | |
Cpanel Cpanel | =6.2 | |
Cpanel Cpanel | =10 | |
Cpanel Cpanel | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.