CVE-2003-0521
Published Aug 18, 2003
Last updated 8 years ago
Overview
- Description
- Cross-site scripting (XSS) vulnerability in cPanel 6.4.2 allows remote attackers to insert arbitrary HTML and possibly gain cPanel administrator privileges via script in a URL that is logged but not properly quoted when displayed via the (1) Error Log or (2) Latest Visitors screens.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Evaluator
- Comment
- -
- Impact
- -
- Solution
- -
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:cpanel:cpanel:5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E5B33AE8-75A8-4454-A1A3-33F4034015FC" }, { "criteria": "cpe:2.3:a:cpanel:cpanel:5.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E4394768-37BE-4FC5-A65A-28C0295A33B6" }, { "criteria": "cpe:2.3:a:cpanel:cpanel:6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DC52A018-43E8-4D86-A84C-81064B6ACD74" }, { "criteria": "cpe:2.3:a:cpanel:cpanel:6.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2FC66D8D-01B8-4312-A311-ACAB43699071" }, { "criteria": "cpe:2.3:a:cpanel:cpanel:6.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E892FB52-DB84-422F-ABB6-29AB95726138" }, { "criteria": "cpe:2.3:a:cpanel:cpanel:6.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1FC5C591-69F3-411F-A53A-72D17687CA2E" }, { "criteria": "cpe:2.3:a:cpanel:cpanel:6.4.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "92D81000-1A7C-4465-9EE2-E651AED09F82" }, { "criteria": "cpe:2.3:a:cpanel:cpanel:6.4.2_stable_48:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E4B555B5-E66F-4E37-A5BC-E04CBDFA4F8B" } ], "operator": "OR" } ] } ]