Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member
    Join Date
    Jan 2005
    Location
    /dev/null
    Posts
    770

    Default Secunia XSS Vunerabilities


  2. #2
    Member
    Join Date
    Jun 2003
    Posts
    280

    Default

    Nope, but it looks low-impacting. To run the exploit scripts, you'll need to be logged into cPanel and only "you" would be affected. I can't see any disclosure of information the user would not be already able to access.

    The only possible thing would be something like tagging onto the end of an exploit link a javascript or reference to a third party site to maybe, possibly, still authenticate credientials. Admittedly, the user (who would still have to login to cPanel) would have to click on that link to get it in affect, but still low impacting IMHO.

    (Should still be patched though )

  3. #3
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    I've seen several such "exploits" in secunia that never make it onto vulndev or bugtraq that are hardly worthy of the name. If anything, they're simply bugs. From the way I read it, you can basically exploit yourself, since as richy points out, you have to be authenticated anyway.
    Last edited by chirpy; 08-22-2006 at 11:27 AM.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  4. #4
    Member
    Join Date
    Jan 2005
    Location
    /dev/null
    Posts
    770

    Default

    I was aware of it only being an issue to a logged in user, and I have to agree with chirpy about secunia's 'vunerabilities' being a bit on the monkey side just thought I'd post it to bring it to people attention, thanks guys

  5. #5
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    Do keep posting them if you find them, they're usually good for a chuckle
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

Similar Threads & Tags
Similar threads

  1. [Case 47329] Mailman - Secunia Advisory SA43389
    By leorevenda in forum Security
    Replies: 2
    Last Post: 03-03-2011, 11:07 AM
  2. XSS Vulnerability
    By rnawky in forum Security
    Replies: 1
    Last Post: 01-13-2011, 12:58 AM
  3. XSS exploit
    By hackman in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 03-26-2008, 05:31 AM
  4. vulns reported by secunia
    By claudio in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 11-14-2006, 11:20 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube