|
News |
|
cPanel WHM Security Advisory |
03-09-2013 |
cPanel & WHM Security Advisory
2013-02-26 cPanel & WHM Security Advisory for 11.32, 11.34, and 11.36
Description
Cross-site scripting attack in countedit.cgi
cPanel & WHM provide an API 2 call that allows branding code to include files that are on the system. This function can also be called remotely. The function did not check that the files requested were within the appropriate document root, so arbitrary files could be read. Additionally, there was the possibility to leverage this with another, third-party vulnerability to execute arbitrary code.
Solution
This issue is resolved in the following builds:
11.36.0.10 and greater
11.34.1.11 and greater
11.32.6.2 and greater
Please update your cPanel & WHM system to one of the aforementioned versions or the latest public release available.
Reference: http://cpanel.net/2013-02-26-cpanel-whm-security-advisory-for-11-32-11-34-and-11-36/ |
Remember, we listen to you! Any comments/suggestions should be sent to info@serverbuddies.com. |
|
|
|
|