CVE-2009-4823: XSS
Published Apr 27, 2010
·Updated
Cross-site scripting (XSS) vulnerability in frontend/x3/files/fileop.html in cPanel 11.0 through 11.24.7 allows remote attackers to inject arbitrary web script or HTML via the fileop parameter.
Affected Software
17 affected components
Cpanel Cpanel=11.0
Cpanel Cpanel=11.18
Cpanel Cpanel=11.4.19
Cpanel Cpanel=11.22
Cpanel Cpanel=11.18.3
Cpanel Cpanel=11.18.1
Cpanel Cpanel=11.22.1
Cpanel Cpanel=11.22.2
Cpanel Cpanel=11.16
Cpanel Cpanel=11.18.4
Cpanel Cpanel=11.21
Cpanel Cpanel=11.21-beta
Cpanel Cpanel=11.24
Cpanel Cpanel=11.22.3
Cpanel Cpanel=11.19.3
Cpanel Cpanel=11.18.2
Cpanel Cpanel=11.24.7
Event History
Apr 27, 2010
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-4823?
CVE-2009-4823 is rated as a medium severity vulnerability due to its potential for cross-site scripting (XSS) exploitation.
2
How do I fix CVE-2009-4823?
To fix CVE-2009-4823, you should upgrade your cPanel installation to a version later than 11.24.7.
3
Which versions of cPanel are affected by CVE-2009-4823?
CVE-2009-4823 affects cPanel versions 11.0 through 11.24.7.
4
What type of vulnerability is CVE-2009-4823?
CVE-2009-4823 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML.
5
Who can exploit CVE-2009-4823?
CVE-2009-4823 can be exploited by remote attackers who can manipulate the fileop parameter in the affected cPanel versions.