Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 2 of 2
  1. #1
    Member
    Join Date
    Jul 2004
    Posts
    102

    Default Cpanel cross site scripting vulnerability

    One can add HTML code to the .lastlogin file. If the root user logs in to this Cpanel user's account the HTML code in the .lastlogin file is shown in the root user's browser. This may be used to read out session information and gain root access or trick the root user into entering the root password again etc. etc.

    Please fix this as soon as possible ! And no, I am not going to submit a bugzilla report cause every time I try I get an error message.

  2. #2
    cPanel Development cpanelkenneth's Avatar
    Join Date
    Apr 2006
    Posts
    3,788
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by driverC View Post
    One can add HTML code to the .lastlogin file. If the root user logs in to this Cpanel user's account the HTML code in the .lastlogin file is shown in the root user's browser. This may be used to read out session information and gain root access or trick the root user into entering the root password again etc. etc.

    Please fix this as soon as possible ! And no, I am not going to submit a bugzilla report cause every time I try I get an error message.
    Security related matters should be directed to security@cpanel.net

    This issue will be addressed. Thank you.

Similar Threads & Tags
Similar threads

  1. cPanel "fileop" Cross-Site Scripting Vulnerability
    By hekri in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 01-04-2010, 08:20 AM
  2. cPanel Multiple Cross-Site Scripting Vulnerabilities
    By leorevenda in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 08-22-2006, 10:17 AM
  3. cPanel User Parameter Cross-Site Scripting Vulnerability [old]
    By maaking in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 07-16-2005, 10:06 AM
  4. cPanel cpsrvd.pl Cross-Site Scripting Vulnerability
    By sr_gireesh in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 06-23-2005, 03:26 AM
  5. Security vulnerability: phpMyAdmin Cross-Site Scripting Vulnerabilities
    By iCARus in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 11-19-2004, 09:51 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube