CVE-2009-4823
Description
Cross-site scripting (XSS) vulnerability in frontend/x3/files/fileop.html in cPanel 11.0 through 11.24.7 allows remote attackers to inject arbitrary web script or HTML via the fileop parameter.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Exploits
Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.
Exploit-DB
cPanel 11.x - 'fileop' Multiple Cross-Site Scripting Vulnerabilities
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| cpanel | cpanel | 11.0 | |
| cpanel | cpanel | 11.4.19 | |
| cpanel | cpanel | 11.16 | |
| cpanel | cpanel | 11.18 | |
| cpanel | cpanel | 11.18.1 | |
| cpanel | cpanel | 11.18.2 | |
| cpanel | cpanel | 11.18.3 | |
| cpanel | cpanel | 11.18.4 | |
| cpanel | cpanel | 11.19.3 | |
| cpanel | cpanel | 11.21 | |
| cpanel | cpanel | 11.22 | |
| cpanel | cpanel | 11.22.1 | |
| cpanel | cpanel | 11.22.2 | |
| cpanel | cpanel | 11.22.3 | |
| cpanel | cpanel | 11.24 | |
| cpanel | cpanel | 11.24.7 | |
References
- http://osvdb.org/61231
- http://secunia.com/advisories/37826
- http://www.cpanel.net/2009/12/cpanel-cross-site-scripting-vulnerability.html
- http://www.exploit-db.com/exploits/10519
- http://www.securityfocus.com/bid/37394
- http://www.vupen.com/english/advisories/2009/3608
- http://osvdb.org/61231
- http://secunia.com/advisories/37826
- http://www.cpanel.net/2009/12/cpanel-cross-site-scripting-vulnerability.html
- http://www.exploit-db.com/exploits/10519
- http://www.securityfocus.com/bid/37394
- http://www.vupen.com/english/advisories/2009/3608
CWEs
CWE-79
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.