Vulnerabilities > CVE-2006-6198 - Cross-Site Scripting vulnerability in Cpanel Webhost Manager 3.1.0
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
SINGLE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Multiple cross-site scripting (XSS) vulnerabilities in cPanel WebHost Manager (WHM) 3.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) email parameter to (a) scripts2/dochangeemail, the (2) supporturl parameter to (b) cgi/addon_configsupport.cgi, the (3) pkg parameter to (c) scripts/editpkg, the (4) domain parameter to (d) scripts2/domts2 and (e) scripts/editzone, the (5) feature parameter to (g) scripts2/dofeaturemanager, and the (6) ndomain parameter to (h) scripts/park.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description cPanel WebHost Manager 3.1 park ndomain Parameter XSS. CVE-2006-6198 . Webapps exploit for php platform id EDB-ID:29188 last seen 2016-02-03 modified 2006-11-25 published 2006-11-25 reporter Aria-Security Team source https://www.exploit-db.com/download/29188/ title cPanel WebHost Manager 3.1 park ndomain Parameter XSS description cPanel WebHost Manager 3.1 domts2 domain Parameter XSS. CVE-2006-6198. Webapps exploit for php platform id EDB-ID:29185 last seen 2016-02-03 modified 2006-11-25 published 2006-11-25 reporter Aria-Security Team source https://www.exploit-db.com/download/29185/ title cPanel WebHost Manager 3.1 domts2 domain Parameter XSS description cPanel WebHost Manager 3.1 dochangeemail email Parameter XSS. CVE-2006-6198 . Webapps exploit for php platform id EDB-ID:29182 last seen 2016-02-03 modified 2006-11-25 published 2006-11-25 reporter Aria-Security Team source https://www.exploit-db.com/download/29182/ title cPanel WebHost Manager 3.1 dochangeemail email Parameter XSS description cPanel WebHost Manager 3.1 addon_configsupport.cgi supporturl Parameter XSS. CVE-2006-6198. Webapps exploit for php platform id EDB-ID:29183 last seen 2016-02-03 modified 2006-11-25 published 2006-11-25 reporter Aria-Security Team source https://www.exploit-db.com/download/29183/ title cPanel WebHost Manager 3.1 addon_configsupport.cgi supporturl Parameter XSS description cPanel WebHost Manager 3.1 dofeaturemanager feature Parameter XSS. CVE-2006-6198. Webapps exploit for php platform id EDB-ID:29187 last seen 2016-02-03 modified 2006-11-25 published 2006-11-25 reporter Aria-Security Team source https://www.exploit-db.com/download/29187/ title cPanel WebHost Manager 3.1 dofeaturemanager feature Parameter XSS description cPanel WebHost Manager 3.1 editzone domain Parameter XSS. CVE-2006-6198. Webapps exploit for php platform id EDB-ID:29186 last seen 2016-02-03 modified 2006-11-25 published 2006-11-25 reporter Aria-Security Team source https://www.exploit-db.com/download/29186/ title cPanel WebHost Manager 3.1 editzone domain Parameter XSS description cPanel WebHost Manager 3.1 editpkg pkg Parameter XSS. CVE-2006-6198. Webapps exploit for php platform id EDB-ID:29184 last seen 2016-02-03 modified 2006-11-25 published 2006-11-25 reporter Aria-Security Team source https://www.exploit-db.com/download/29184/ title cPanel WebHost Manager 3.1 editpkg pkg Parameter XSS