Vulnerabilities > CVE-2006-4293 - Cross-Site Scripting vulnerability in Cpanel 10

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
cpanel
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote attackers to inject arbitrary web script or HTML via the (1) dir parameter in dohtaccess.html, or the (2) file parameter in (a) editit.html or (b) showfile.html.

Vulnerable Configurations

Part Description Count
Application
Cpanel
1

Exploit-Db

  • descriptioncPanel 10.x dohtaccess.html dir Parameter XSS. CVE-2006-4293. Webapps exploit for php platform
    idEDB-ID:28413
    last seen2016-02-03
    modified2006-08-21
    published2006-08-21
    reporterpreth00nker
    sourcehttps://www.exploit-db.com/download/28413/
    titlecPanel 10.x dohtaccess.html dir Parameter XSS
  • descriptioncPanel 10.x showfile.html file Parameter XSS. CVE-2006-4293 . Webapps exploit for php platform
    idEDB-ID:28415
    last seen2016-02-03
    modified2006-08-21
    published2006-08-21
    reporterpreth00nker
    sourcehttps://www.exploit-db.com/download/28415/
    titlecPanel 10.x showfile.html file Parameter XSS
  • descriptioncPanel 10.x editit.html file Parameter XSS. CVE-2006-4293. Webapps exploit for php platform
    idEDB-ID:28414
    last seen2016-02-03
    modified2006-08-21
    published2006-08-21
    reporterpreth00nker
    sourcehttps://www.exploit-db.com/download/28414/
    titlecPanel 10.x editit.html file Parameter XSS