CVE-2009-4823
cPanel 11.0-11.24.7 - Cross-Site Scripting via Fileop Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4823. PoCs published by RENO.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in cPanel versions prior to 11.25.0. It includes example URLs demonstrating how an attacker could exploit the vulnerability by injecting arbitrary script code into the browser of an unsuspecting user.
Description
Cross-site scripting (XSS) vulnerability in frontend/x3/files/fileop.html in cPanel 11.0 through 11.24.7 allows remote attackers to inject arbitrary web script or HTML via the fileop parameter.
Exploits (1)
The provided text describes a cross-site scripting (XSS) vulnerability in cPanel versions prior to 11.25.0. It includes example URLs demonstrating how an attacker could exploit the vulnerability by injecting arbitrary script code into the browser of an unsuspecting user.