First published: Mon Aug 10 2009(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Module for cPanel allow remote attackers to inject arbitrary web script or HTML via the (1) localapp, (2) updatedir, (3) scriptpath_show, (4) domain_show, (5) thispage, (6) thisapp, and (7) currentversion parameters in an Upgrade action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cpanel Cpanel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-6927 is classified as a medium severity vulnerability due to its potential for exploitation through cross-site scripting.
To mitigate CVE-2008-6927, you should update the Fantastico De Luxe Module for cPanel to the latest version that addresses the XSS vulnerabilities.
CVE-2008-6927 can be exploited through cross-site scripting attacks that allow attackers to inject malicious scripts into web pages.
CVE-2008-6927 affects the Fantastico De Luxe Module used in cPanel installations.
Yes, CVE-2008-6927 can compromise your website's security by allowing unauthorized scripts to execute in the context of your users' browsers.