Vulnerabilities > CVE-2006-6198 - Unspecified vulnerability in Cpanel Webhost Manager 3.1.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN cpanel
exploit available
Summary
Multiple cross-site scripting (XSS) vulnerabilities in cPanel WebHost Manager (WHM) 3.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) email parameter to (a) scripts2/dochangeemail, the (2) supporturl parameter to (b) cgi/addon_configsupport.cgi, the (3) pkg parameter to (c) scripts/editpkg, the (4) domain parameter to (d) scripts2/domts2 and (e) scripts/editzone, the (5) feature parameter to (g) scripts2/dofeaturemanager, and the (6) ndomain parameter to (h) scripts/park.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description cPanel WebHost Manager 3.1 park ndomain Parameter XSS. CVE-2006-6198 . Webapps exploit for php platform id EDB-ID:29188 last seen 2016-02-03 modified 2006-11-25 published 2006-11-25 reporter Aria-Security Team source https://www.exploit-db.com/download/29188/ title cPanel WebHost Manager 3.1 park ndomain Parameter XSS description cPanel WebHost Manager 3.1 domts2 domain Parameter XSS. CVE-2006-6198. Webapps exploit for php platform id EDB-ID:29185 last seen 2016-02-03 modified 2006-11-25 published 2006-11-25 reporter Aria-Security Team source https://www.exploit-db.com/download/29185/ title cPanel WebHost Manager 3.1 domts2 domain Parameter XSS description cPanel WebHost Manager 3.1 dochangeemail email Parameter XSS. CVE-2006-6198 . Webapps exploit for php platform id EDB-ID:29182 last seen 2016-02-03 modified 2006-11-25 published 2006-11-25 reporter Aria-Security Team source https://www.exploit-db.com/download/29182/ title cPanel WebHost Manager 3.1 dochangeemail email Parameter XSS description cPanel WebHost Manager 3.1 addon_configsupport.cgi supporturl Parameter XSS. CVE-2006-6198. Webapps exploit for php platform id EDB-ID:29183 last seen 2016-02-03 modified 2006-11-25 published 2006-11-25 reporter Aria-Security Team source https://www.exploit-db.com/download/29183/ title cPanel WebHost Manager 3.1 addon_configsupport.cgi supporturl Parameter XSS description cPanel WebHost Manager 3.1 dofeaturemanager feature Parameter XSS. CVE-2006-6198. Webapps exploit for php platform id EDB-ID:29187 last seen 2016-02-03 modified 2006-11-25 published 2006-11-25 reporter Aria-Security Team source https://www.exploit-db.com/download/29187/ title cPanel WebHost Manager 3.1 dofeaturemanager feature Parameter XSS description cPanel WebHost Manager 3.1 editzone domain Parameter XSS. CVE-2006-6198. Webapps exploit for php platform id EDB-ID:29186 last seen 2016-02-03 modified 2006-11-25 published 2006-11-25 reporter Aria-Security Team source https://www.exploit-db.com/download/29186/ title cPanel WebHost Manager 3.1 editzone domain Parameter XSS description cPanel WebHost Manager 3.1 editpkg pkg Parameter XSS. CVE-2006-6198. Webapps exploit for php platform id EDB-ID:29184 last seen 2016-02-03 modified 2006-11-25 published 2006-11-25 reporter Aria-Security Team source https://www.exploit-db.com/download/29184/ title cPanel WebHost Manager 3.1 editpkg pkg Parameter XSS
References
- http://securityreason.com/securityalert/1938
- http://securityreason.com/securityalert/1938
- http://www.aria-security.com/forum/showthread.php?t=44
- http://www.aria-security.com/forum/showthread.php?t=44
- http://www.securityfocus.com/archive/1/452618/100/0/threaded
- http://www.securityfocus.com/archive/1/452618/100/0/threaded
- http://www.securityfocus.com/bid/21288
- http://www.securityfocus.com/bid/21288
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30507
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30507