CVE Database
/

CVE-2004-1875

Back to search

CVE-2004-1875

Published: May 10, 2005

Modified: Aug 8, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0-R85 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to testfile.html, (2) file parameter to erredit.html, (3) dns parameter to dnslook.html, (4) account parameter to ignorelist.html, (5) account parameter to showlog.html, (6) db parameter to repairdb.html, (7) login parameter to doaddftp.html (8) account parameter to editmsg.htm, or (9) ip parameter to del.html. NOTE: the dnslook.html vector was later reported to exist in cPanel 10.

VendorProductVersions

n/a

n/a

affected
n/a

References

4243
vdb-entry
x_refsource_OSVDB
20040330 Exensive cPanel Cross Site Scripting
mailing-list
x_refsource_BUGTRAQ
21142
vdb-entry
x_refsource_BID
11244
third-party-advisory
x_refsource_SECUNIA
4215
vdb-entry
x_refsource_OSVDB
4210
vdb-entry
x_refsource_OSVDB
cpanel-multiple-scripts-xss(15671)
vdb-entry
x_refsource_XF
22984
third-party-advisory
x_refsource_SECUNIA
4211
vdb-entry
x_refsource_OSVDB
ADV-2006-4658
vdb-entry
x_refsource_VUPEN
10002
vdb-entry
x_refsource_BID
4212
vdb-entry
x_refsource_OSVDB
4208
vdb-entry
x_refsource_OSVDB
4213
vdb-entry
x_refsource_OSVDB
4214
vdb-entry
x_refsource_OSVDB
4209
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now