CVE-2006-6198: XSS
Multiple cross-site scripting (XSS) vulnerabilities in cPanel WebHost Manager (WHM) 3.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) email parameter to (a) scripts2/dochangeemail, the (2) supporturl parameter to (b) cgi/addonconfigsupport.cgi, the (3) pkg parameter to (c) scripts/editpkg, the (4) domain parameter to (d) scripts2/domts2 and (e) scripts/editzone, the (5) feature parameter to (g) scripts2/dofeaturemanager, and the (6) ndomain parameter to (h) scripts/park.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6198?
The severity of CVE-2006-6198 is high due to its potential for allowing remote authenticated users to execute arbitrary JavaScript or HTML.
How do I fix CVE-2006-6198?
To fix CVE-2006-6198, update cPanel WebHost Manager to the latest version that addresses these XSS vulnerabilities.
Who is affected by CVE-2006-6198?
CVE-2006-6198 affects users of cPanel WebHost Manager version 3.1.0, specifically those with remote authentication.
What types of vulnerabilities does CVE-2006-6198 contain?
CVE-2006-6198 contains multiple cross-site scripting (XSS) vulnerabilities that can be exploited to inject malicious scripts.
Can CVE-2006-6198 be exploited remotely?
Yes, CVE-2006-6198 can be exploited remotely by authenticated users who manipulate specific parameters.