Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allows remote attackers to bypass XSS protection and inject arbitrary script or HTML via repeated, improperly-ordered "<" and ">" characters in the (1) issue parameter to scripts2/knowlegebase, (2) user parameter to scripts2/changeip, (3) search parameter to scripts2/listaccts, and other unspecified vectors.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
cPanel多个跨站脚本和跨站请求伪造漏洞
Vulnerability Description
cPanel是基于web的工具,用于自动化控制网站和服务器。 cPanel的WHM接口允许用户管理和访问cPanel及WHM软件包的核心。这个接口没有正确地防范跨站脚本和跨站请求伪造攻击,允许远程攻击者通过提交恶意请求在服务器上执行任意代码。 所有管理用户输入的函数都存在跨站脚本漏洞,以下为部分有漏洞的函数列表: * Knowlege Base(/scripts2/knowlegebase?issue=[INJECTION]&domain=) * Change Ip to domain(/scripts2
CVSS Information
N/A
Vulnerability Type
N/A