CVE-2008-2070: XSS
The WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allows remote attackers to bypass XSS protection and inject arbitrary script or HTML via repeated, improperly-ordered "<" and ">" characters in the (1) issue parameter to scripts2/knowlegebase, (2) user parameter to scripts2/changeip, (3) search parameter to scripts2/listaccts, and other unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2070?
CVE-2008-2070 is classified as a high severity vulnerability due to its impact on XSS protection.
How do I fix CVE-2008-2070?
To fix CVE-2008-2070, upgrade to cPanel version 11.18.4 or later, or version 11.22.3 or later.
Who is affected by CVE-2008-2070?
CVE-2008-2070 affects cPanel versions 11.18 before 11.18.4 and 11.22 before 11.22.3.
What types of attacks are possible with CVE-2008-2070?
CVE-2008-2070 allows remote attackers to inject arbitrary scripts or HTML into the WHM interface.
Is CVE-2008-2070 a critical vulnerability?
While not classified as critical, CVE-2008-2070 poses significant risk due to potential XSS exploitation.