[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

cPanel WebHost Manager 3.1 dofeaturemanager feature Parameter XSS

Author
Aria-Security
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-21441
Category
web applications
Date add
01-11-2013
Platform
php
source: http://www.securityfocus.com/bid/21288/info
      
WebHost Manager is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
      
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
      
WebHost Manager version 3.1.0 is vulnerable; other versions may also be affected.
 
http://www.example.com:2086/scripts2/dofeaturemanager?action=addfeature&feature=XSS

#  0day.today [2024-11-16]  #