CVE-2008-2478: Code Injection
DISPUTED scripts/wwwacct in cPanel 11.18.6 STABLE and earlier and 11.23.1 CURRENT and earlier allows remote authenticated users with reseller privileges to execute arbitrary code via shell metacharacters in the Email address field (aka Email text box). NOTE: the vendor disputes this, stating "I'm unable to reproduce such an issue on multiple servers running different versions of cPanel."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2478?
CVE-2008-2478 is classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2008-2478?
To mitigate CVE-2008-2478, update cPanel to a version that is higher than 11.18.6 STABLE or 11.23.1 CURRENT.
What impact does CVE-2008-2478 have on systems?
CVE-2008-2478 allows authenticated users with reseller privileges to execute arbitrary code, potentially compromising the server.
Who is affected by CVE-2008-2478?
CVE-2008-2478 affects users of cPanel versions 11.18.6 STABLE and earlier as well as 11.23.1 CURRENT and earlier.
Is CVE-2008-2478 a widely exploited vulnerability?
CVE-2008-2478 has been disputed by the vendor, and its exploitation may vary, but caution is advised for affected versions.