Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 9 of 9
  1. #1
    Member
    Join Date
    Mar 2004
    Posts
    5

    Default XSS vunerability

    For those that havn't seen it: http://news.almostinspired.co.uk/art....lists.bugtraq

    Why don't cPanel change the release version so we don't all have to force upgrades to the EDGE version?

    Fix/Workaround:
    Upgrade to the April 1, 2004 EDGE release or newer.
    That's funny 'cause it isn't 01 Apr yet
    Last edited by xela; 03-31-2004 at 01:46 AM.

  2. #2
    Member bamasbest's Avatar
    Join Date
    Jan 2004
    Posts
    531

    Default

    As a rule of thumb, you would never catch me doing anyhting on April Fool's Day

  3. #3
    Member
    Join Date
    Sep 2003
    Posts
    68

    Default

    9.1.0-STABLE_93

    Is Effected

  4. #4
    Member
    Join Date
    Sep 2003
    Posts
    126

    Default

    install mod_security and gain rules to protect from XSS attacks.

  5. #5
    Member
    Join Date
    Oct 2003
    Posts
    1,020

    Default

    We need an acronym registry!

    I came here wondering in what way Cascading Style Sheets were vulnerable and how it applied to cPanel installs.

  6. #6
    Member
    Join Date
    Mar 2004
    Posts
    5

    Default

    Changed to an "X", just for you

  7. #7
    Member casey's Avatar
    Join Date
    Jan 2003
    Location
    If there is trouble, it will find me
    Posts
    2,336

    Default

    Originally posted by fleksi
    install mod_security and gain rules to protect from XSS attacks.
    cpanel doesn't use the apache on port 80, so I don't think that's an option in this case. I have mod_security installed, and mine is still vulnerable. 9.1.0 current 65.

  8. #8
    Member
    Join Date
    Oct 2002
    Posts
    751

    Default

    Originally posted by fleksi
    install mod_security and gain rules to protect from XSS attacks.
    How did you install mod_security on the cpanel webserver?

    I am running mod_security on my server, but Cpanel (port 2083 etc.) doesn't run on the apache webserver you use to serve your websites with. It uses a separate webserver.

    EDIT : Casey was one step ahead of me

  9. #9
    Member casey's Avatar
    Join Date
    Jan 2003
    Location
    If there is trouble, it will find me
    Posts
    2,336

    Default

    Originally posted by jamesbond
    EDIT : Casey was one step ahead of me
    Ha, ha.

Similar Threads & Tags
Similar threads

  1. Apacher/mod_ssl vunerability
    By haswalt in forum Archived Feature Requests
    Replies: 1
    Last Post: 09-03-2010, 12:10 PM
  2. Apacher/mod_ssl vunerability
    By haswalt in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 11-09-2009, 04:03 AM
  3. CSS in Cpanel
    By Emmanue in forum New User Questions
    Replies: 1
    Last Post: 09-15-2008, 09:57 AM
  4. CSS gone?
    By darkshadow604 in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 10-22-2007, 12:41 PM
  5. uw-imapd vunerability question
    By abubin in forum New User Questions
    Replies: 11
    Last Post: 10-09-2005, 09:48 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube