CVE-2008-2070 – cPanel 11.x - '/scripts2/changeip?user' Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2008-2070
09 May 2008 — The WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allows remote attackers to bypass XSS protection and inject arbitrary script or HTML via repeated, improperly-ordered "<" and ">" characters in the (1) issue parameter to scripts2/knowlegebase, (2) user parameter to scripts2/changeip, (3) search parameter to scripts2/listaccts, and other unspecified vectors. La interfaz WHM 11.15.0 para cPanel 11.18 anterior a 11.18.4 y 11.22 anterior a 11.22.3 permite a atacantes remotos evi... • https://www.exploit-db.com/exploits/31772 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2008-2071
https://notcve.org/view.php?id=CVE-2008-2071
09 May 2008 — Multiple cross-site request forgery (CSRF) vulnerabilities in the WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allow remote attackers to perform unauthorized actions as cPanel administrators via requests to cpanel/whm/webmail and other unspecified vectors. Múltiples vulnerabilidades de falsificación de petición en sitios cruzados (CSRF) en la interfaz WHM 11.15.0 para cPanel 11.18 anterior a 11.18.4 y 11.22 anterior a 11.22.3 permite a atacantes remotos realizar acciones si... • http://changelog.cpanel.net/?revision=0%3Btree=%3Btreeview=%3Bshow=html%3Bpp=25%3Bte=1314%3Bpg=2 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2008-2043
https://notcve.org/view.php?id=CVE-2008-2043
01 May 2008 — Multiple cross-site request forgery (CSRF) vulnerabilities in cPanel, possibly 11.18.3 and 11.19.3, allow remote attackers to (1) execute arbitrary code via the command1 parameter to frontend/x2/cron/editcronsimple.html, and perform various administrative actions via (2) frontend/x2/sql/adddb.html, (3) frontend/x2/sql/adduser.html, and (4) frontend/x2/ftp/doaddftp.html. Múltiples vulnerabilidades de falsificación de petición en sitios cruzados (CSRF) en cPanel, posiblemente 11.18.3 y 11.19.3, permite a los ... • http://secunia.com/advisories/30027 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2008-1499 – cPanel 11.18.3/11.21 - 'manpage.html' Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2008-1499
25 Mar 2008 — Cross-site scripting (XSS) vulnerability in frontend/x/manpage.html in cPanel 11.18.3 and 11.21.0-BETA allows remote attackers to inject arbitrary web script or HTML via the query string. Vulnerabilidad de secuencia de comandos en sitios cruzados (XSS) en frontend/x/manpage.html de cPanel 11.18.3 y 11.21.0-BETA, permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección mediante una cadena de consulta. • https://www.exploit-db.com/exploits/31472 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2008-0370
https://notcve.org/view.php?id=CVE-2008-0370
22 Jan 2008 — Cross-site scripting (XSS) vulnerability in dohtaccess.html in cPanel before 11.17 build 19417 allows remote attackers to inject arbitrary web script or HTML via the rurl parameter. NOTE: some of these details are obtained from third party information. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en dohtaccess.html en cPanel anterior a 11.17 construcción 19417 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro rurl. NOTA: algunos de estos detal... • http://aria-security.net/forum/showthread.php?p=1238 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2007-4022 – cPanel 10.9.1 - 'Resname' Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2007-4022
26 Jul 2007 — Cross-site scripting (XSS) vulnerability in frontend/x/htaccess/changepro.html in cPanel 10.9.1 allows remote attackers to inject arbitrary web script or HTML via the resname parameter. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el frontend/x/htaccess/changepro.html del cPanel 10.9.1 permiten a atacantes remotos la inyección de secuencias de comandos web o HTML de su elección a través del parámetro resname. • https://www.exploit-db.com/exploits/30380 •
CVE-2007-3366
https://notcve.org/view.php?id=CVE-2007-3366
22 Jun 2007 — Cross-site scripting (XSS) vulnerability in Simple CGI Wrapper (scgiwrap) in cPanel before 10.9.1, and 11.x before 11.4.19-R14378, allows remote attackers to inject arbitrary web script or HTML via the URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Simple CGI Wrapper (scgiwrap) de cPanel versiones anteriores a 10.9.1, y 11.x versiones anteriores a 11.4.19-R14378, perm... • http://osvdb.org/35860 •
CVE-2007-3367
https://notcve.org/view.php?id=CVE-2007-3367
22 Jun 2007 — Simple CGI Wrapper (scgiwrap) in cPanel before 10.9.1, and 11.x before 11.4.19-R14378, allows remote attackers to obtain sensitive information via a direct request, which reveals the path in an error message. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Simple CGI Wrapper (scgiwrap) de cPanel versiones anteriores a 10.9.1, y 11.x versiones anteriores a 11.4.19-R14378, permite a atacantes remotos obtener información confidencial mediante u... • http://osvdb.org/35861 •
CVE-2007-1455 – cPanel 10.9.x - 'Fantastico' Local File Inclusion
https://notcve.org/view.php?id=CVE-2007-1455
14 Mar 2007 — Multiple absolute path traversal vulnerabilities in Fantastico, as used with cPanel 10.x, allow remote authenticated users to include and execute arbitrary local files via (1) the userlanguage parameter to includes/load_language.php or (2) the fantasticopath parameter to includes/mysqlconfig.php and certain other files. Múltiples vulnerabilidades de de escalado de ruta absoluta en el Fantastico, como el utilizado en el cPanel 10.x, permite a usuarios remotos autenticados incluir y ejecutar ficheros locales ... • https://www.exploit-db.com/exploits/3459 •
CVE-2007-0890 – cPanel 11 - PassWDMySQL Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2007-0890
12 Feb 2007 — Cross-site scripting (XSS) vulnerability in scripts/passwdmysql in cPanel WebHost Manager (WHM) 11.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the password parameter. Vulnerabilidad de secuencia de comandos en sitios cruzados (XSS) en scripts/passwdmysql en cPanel WebHost Manager (WHM) 11.0.0 y anteriores permite a un atacante remoto inyectar secuencias de comandos web o HTML a través del parámetro password. • https://www.exploit-db.com/exploits/29572 •