Multiple cross-site scripting (XSS) vulnerabilities in InterWorx Hosting Control Panel (InterWorx-CP) Webmaster Level (SiteWorx) 3.0.2 (1) allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php; and allow remote authenticated users to inject arbitrary web script or HTML via the PATH_INFO to (2) siteworx.php, (3) users.php, (4) ftp.php, (5) mysql.php, (6) domains.php, (7) htaccess.php, (8) scriptworx.php, (9) stats.php, (10) backup.php, (11) restore.php, and (12) httpd.php; and unspecified vectors to (13) cron.php and (14) prefs.php.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://osvdb.org/36778 | vdb entry |
http://www.securityfocus.com/bid/25451 | vdb entry |
http://securityreason.com/securityalert/3070 | third party advisory |
http://interworx.com/forums/showthread.php?t=2501 | |
http://osvdb.org/36772 | vdb entry |
http://osvdb.org/36775 | vdb entry |
http://osvdb.org/36771 | vdb entry |
http://osvdb.org/36776 | vdb entry |
http://osvdb.org/36773 | vdb entry |
http://osvdb.org/36780 | vdb entry |
http://osvdb.org/36779 | vdb entry |
http://osvdb.org/36768 | vdb entry |
http://osvdb.org/36774 | vdb entry |
http://www.hackerscenter.com/archive/view.asp?id=27884 | |
http://secunia.com/advisories/26586 | third party advisory |
http://www.securityfocus.com/archive/1/477848/100/0/threaded | mailing list |
http://osvdb.org/36777 | vdb entry |
http://osvdb.org/36769 | vdb entry |
http://osvdb.org/36767 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/36300 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/36297 | vdb entry |
http://osvdb.org/36770 | vdb entry |