Matteo Carli

3 exploits Active since May 2008
CVE-2008-2070 EXPLOITDB text WRITEUP
cPanel 11.15.0-11.18.3 and 11.22-11.22.2 - Cross-Site Scripting via Malformed HTML Tags
The WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allows remote attackers to bypass XSS protection and inject arbitrary script or HTML via repeated, improperly-ordered "<" and ">" characters in the (1) issue parameter to scripts2/knowlegebase, (2) user parameter to scripts2/changeip, (3) search parameter to scripts2/listaccts, and other unspecified vectors.
CVE-2008-2070 EXPLOITDB text WRITEUP
cPanel 11.15.0-11.18.3 and 11.22-11.22.2 - Cross-Site Scripting via Malformed HTML Tags
The WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allows remote attackers to bypass XSS protection and inject arbitrary script or HTML via repeated, improperly-ordered "<" and ">" characters in the (1) issue parameter to scripts2/knowlegebase, (2) user parameter to scripts2/changeip, (3) search parameter to scripts2/listaccts, and other unspecified vectors.
CVE-2008-2070 EXPLOITDB text WRITEUP
cPanel 11.15.0-11.18.3 and 11.22-11.22.2 - Cross-Site Scripting via Malformed HTML Tags
The WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allows remote attackers to bypass XSS protection and inject arbitrary script or HTML via repeated, improperly-ordered "<" and ">" characters in the (1) issue parameter to scripts2/knowlegebase, (2) user parameter to scripts2/changeip, (3) search parameter to scripts2/listaccts, and other unspecified vectors.