8.5
CVSSv2

CVE-2008-2478

Published: 28/05/2008 Updated: 11/04/2024
CVSS v2 Base Score: 8.5 | Impact Score: 10 | Exploitability Score: 6.8
VMScore: 855
Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Summary

scripts/wwwacct in cPanel 11.18.6 STABLE and previous versions and 11.23.1 CURRENT and previous versions allows remote authenticated users with reseller privileges to execute arbitrary code via shell metacharacters in the Email address field (aka Email text box). NOTE: the vendor disputes this, stating "I'm unable to reproduce such an issue on multiple servers running different versions of cPanel.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cpanel cpanel

Exploits

source: wwwsecurityfocuscom/bid/29277/info cPanel is prone to a remote privilege-escalation vulnerability because of an unspecified error Successfully exploiting this issue allows remote attackers to gain administrative privileges to the affected application and execute malicious PHP code in the context of the webserver process This ma ...