CVE-2008-2070
Published May 12, 2008
Last updated a year ago
Overview
- Description
- The WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allows remote attackers to bypass XSS protection and inject arbitrary script or HTML via repeated, improperly-ordered "<" and ">" characters in the (1) issue parameter to scripts2/knowlegebase, (2) user parameter to scripts2/changeip, (3) search parameter to scripts2/listaccts, and other unspecified vectors.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:cpanel:cpanel:11.18:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CF562242-C032-4D52-9464-91EF5C9EEA9A" }, { "criteria": "cpe:2.3:a:cpanel:cpanel:11.18.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "80AD4CE4-714E-4949-B676-F1F692172773" }, { "criteria": "cpe:2.3:a:cpanel:cpanel:11.18.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6FAC2F2A-3A9C-4B7D-8B20-4DBEB6DF9532" }, { "criteria": "cpe:2.3:a:cpanel:cpanel:11.18.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "53A19523-B3B1-48E6-A202-CEB1CBD2DDB4" }, { "criteria": "cpe:2.3:a:cpanel:cpanel:11.22:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "67891987-C727-45FF-B027-11B25D2849D3" }, { "criteria": "cpe:2.3:a:cpanel:cpanel:11.22.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "011314F7-1977-453B-B308-DB776DF604E2" }, { "criteria": "cpe:2.3:a:cpanel:cpanel:11.22.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "051B4B2E-BF9B-4EA8-973B-6D96A1618F24" } ], "operator": "OR" } ] } ]