← Back

CVE-2008-2478

nvd nist
Published: May 28, 2008Modified: Apr 23, 2026

JSON object

Loading...
8.5
Vector
AV:N/AC:M/Au:S/C:C/I:C/A:C
Exploitability: 6.8 / Impact: 10.0
Source: NVD

Description

scripts/wwwacct in cPanel 11.18.6 STABLE and earlier and 11.23.1 CURRENT and earlier allows remote authenticated users with reseller privileges to execute arbitrary code via shell metacharacters in the Email address field (aka Email text box). NOTE: the vendor disputes this, stating "I'm unable to reproduce such an issue on multiple servers running different versions of cPanel.

Affected (2)

Products: Cpanel: Cpanel
1 product
Cpanel
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Cpanel
Up to 11.23.1
Up to 11.8.6

References (10)

Timeline

No history available yet.