← Back

CVE-2008-2070

nvd nist
Published: May 12, 2008Modified: Apr 23, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

The WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allows remote attackers to bypass XSS protection and inject arbitrary script or HTML via repeated, improperly-ordered "<" and ">" characters in the (1) issue parameter to scripts2/knowlegebase, (2) user parameter to scripts2/changeip, (3) search parameter to scripts2/listaccts, and other unspecified vectors.

Affected (7)

Products: Cpanel: Cpanel
1 product
Cpanel
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Cpanel
Version 11.18.1
Version 11.18.2
Version 11.18.3
Version 11.18
Version 11.22.1
Version 11.22.2
Version 11.22

Timeline

No history available yet.