CVE-2012-6448
MEDIUMcPanel WebHost Manager 11.34.0 - Cross-Site Scripting
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-6448. PoCs published by Christy Philip Mathew.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in cPanel and WHM versions 11.34.0. It includes a proof-of-concept URL demonstrating the XSS via unsanitized input in the 'acct' parameter.
Description
Cross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 11.34.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Christy Philip Mathew · textwebappsphp
https://www.exploit-db.com/exploits/38153
The provided text describes a cross-site scripting (XSS) vulnerability in cPanel and WHM versions 11.34.0. It includes a proof-of-concept URL demonstrating the XSS via unsanitized input in the 'acct' parameter.
Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target:
cPanel 11.34.0 and WHM 11.34.0
No auth needed
Prerequisites:
Access to the vulnerable URL endpoint
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (1)
Core 1
Core References
Third Party Advisory, VDB Entry exploit
x_refsource_exploit-db
https://www.exploit-db.com/exploits/38153
Scores
CVSS v3
6.1
EPSS
0.0153
EPSS Percentile
71.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
cpanel/webhost_manager
11.34.0
Published
Jan 27, 2020
Tracked Since
Feb 18, 2026