CVE-2006-6548: XSS
Multiple cross-site scripting (XSS) vulnerabilities in cPanel WebHost Manager (WHM) 3.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the domain parameter to (1) scripts2/changeemail, (2) scripts2/limitbw, or (3) scripts/rearrangeacct. NOTE: the feature parameter to scripts2/dofeaturemanager is already covered by CVE-2006-6198.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6548?
CVE-2006-6548 is classified as a high severity vulnerability due to its potential to allow remote authenticated users to launch cross-site scripting attacks.
How do I fix CVE-2006-6548?
To remediate CVE-2006-6548, it is recommended to update cPanel WebHost Manager to a version that addresses this XSS vulnerability.
Who is affected by CVE-2006-6548?
CVE-2006-6548 affects users of cPanel WebHost Manager version 3.1.0, particularly those with remote authenticated access.
What types of attacks can CVE-2006-6548 facilitate?
CVE-2006-6548 can facilitate cross-site scripting (XSS) attacks, allowing the injection of arbitrary web scripts or HTML.
What are the specific functions impacted by CVE-2006-6548?
CVE-2006-6548 affects the domain parameter in the scripts2/changeemail, scripts2/limitbw, and scripts/rearrangeacct functions.