CVE-2006-4293

Cpanel - XSS

Title source: rule
STIX 2.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote attackers to inject arbitrary web script or HTML via the (1) dir parameter in dohtaccess.html, or the (2) file parameter in (a) editit.html or (b) showfile.html.

Exploits (3)

exploitdb WRITEUP VERIFIED
by preth00nker · textwebappsphp
https://www.exploit-db.com/exploits/28415
exploitdb WRITEUP VERIFIED
by preth00nker · textwebappsphp
https://www.exploit-db.com/exploits/28414
exploitdb WRITEUP VERIFIED
by preth00nker · textwebappsphp
https://www.exploit-db.com/exploits/28413

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/28447
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/28043
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/19624
Exploit, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21592
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/443637/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/28041
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1442
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/28042

Scores

EPSS 0.0193
EPSS Percentile 83.5%

Details

Status published
Products (1)
cpanel/cpanel 10
Published Aug 22, 2006
Tracked Since Feb 18, 2026