Vulnerabilities > CVE-2005-2021 - Cross-Site Scripting vulnerability in cPanel User Parameter

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
cpanel
nessus
exploit available

Summary

Cross-site scripting (XSS) vulnerability in cPanel 9.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the user parameter in the login page.

Exploit-Db

descriptioncPanel 9.1 User Parameter Cross-Site Scripting Vulnerability. CVE-2005-2021 . Webapps exploit for php platform
idEDB-ID:25846
last seen2016-02-03
modified2005-05-20
published2005-05-20
reporter[email protected]
sourcehttps://www.exploit-db.com/download/25846/
titlecPanel <= 9.1 User Parameter Cross-Site Scripting Vulnerability

Nessus

NASL familyCGI abuses : XSS
NASL idCPANEL_LOGIN_USER_XSS.NASL
descriptionThe remote host is running cPanel. The version of cPanel on the remote host suffers from a cross-site scripting vulnerability due to its failure to sanitize user-supplied input to the
last seen2020-06-01
modified2020-06-02
plugin id18540
published2005-06-21
reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/18540
titlecPanel cpsrvd.pl user Parameter XSS