hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : cPanel Malicious HTML Tags Injection Vulnerability
Reply

Hosting Security and Technology Configuring and optimizing web hosting servers and operating systems, developing administration scripts, building servers, protecting against hackers, and general security (SSL certificates, etc.)
Forum Jump

cPanel Malicious HTML Tags Injection Vulnerability

Reply Post New Thread In Hosting Security and Technology Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 07-07-2003, 03:19 PM
eBoundary eBoundary is offline
Web Hosting Master
 
Join Date: May 2003
Location: Philadelphia
Posts: 968

cPanel Malicious HTML Tags Injection Vulnerability


From: Ory Segal <ory.segal@sanctuminc.com>
Date: Sun Jul 6, 2003 4:46:44 AM US/Eastern
To: BUGTRAQ@SECURITYFOCUS.COM, full-disclosure@lists.netsys.com, webappsec@securityfocus.com
Subject: cPanel Malicious HTML Tags Injection Vulnerability

-------------------------------------------------------------------------------
-----[ cPanel Malicious HTML Tags Injection Vulnerability
-------------------------------------------------------------------------------

--[ Author: Ory Segal, Sanctum inc. http://www.SanctumInc.com
--[ Discovery Date: 06/17/2003 (Vendor was notified)
--[ Release Date: 07/06/2003
--[ Product: Tested on cPanel 6.4.2-STABLE
--[ Severity: Medium
--[ CVE: Not assigned yet

--[ Summary

From the vendor's web site:
"...The Cpanel interface is a client side interface, which allows your customers
to easily control a web hosting account. With the touch of a button, they can
add e-mail accounts, access their files, backup their files, setup a shopping
cart, and more..."

Web users can embed Malicious HTML tags in HTTP requests, which will later
be parsed by the web site administrator's browser, in several cPanel screens.
This may lead to theft of cookies associated with the domain, or execution of
client-side scripts in the administrator's browser.
--[ Description

The 'Error Log' and 'Latest Visitors' screens in cPanel, provide the web site
administrator with HTTP request logs. These scripts do not sanitize the URL part
of HTTP requests and present them to the administrator as is, thus, allowing an
attacker to embed malicious HTML tags that will later be parsed and executed by
the administrators browser.

For example, lets take a look at the 'Error Log' screen:

[From errlog.html]
...
<b>Last 300 Error Log Messages in reverse order:</b><hr>
<pre>
[Tue Jun 17 08:41:14 2003] [error] [client x.x.x.x] File does not exist:
/home/dir/public_html/foobar.html
</pre>
...

The following request will present a pop-up screen with the cookies
that are currently associated with the domain:

GET /<script>alert(document.cookie);</script> HTTP/1.0
Host: www.site.com


--[ Note

The 'Latest Visitors' screen of the tested version (6.4.2-STABLE) presented the
latest requests as HTML links, thus the malicious payload must terminate the <a>
tag before opening a new one. For example:

GET /"></a><script>alert(document.cookie);</script> HTTP/1.0
Host: www.site.com

--[ Solution

According to the vendor, the problem was fixed in version 7.0, which can be
downloaded at: http://www.cpanel.net/downloads.htm

__________________
http://www.eBoundary.com - Let us help you expand your eBoundaries!
Fast, Secure and reliable FreeBSD shared, reseller and dedicated hosting.
FREE Peace of mind with every account!

Reply With Quote


Sponsored Links
Reply

Related posts from TheWhir.com
Title Type Date Posted
Heroku Works with Security Researcher to Fix Password Vulnerability Web Hosting News 2013-01-10 12:51:17
cPanel Security Updates Address Perl Module Vulnerabilities Web Hosting News 2012-12-06 12:55:54
cPanel Conference 2012: Branding and How to Do it Better with Felipe Gasper Web Hosting News 2012-10-09 18:00:02
5 Major Malware Threats Facing Web Hosting Providers Web Hosting News 2012-02-17 16:16:34
cPanel to Launch Certification Program at cPanel Conference 2011 Web Hosting News 2011-09-21 18:15:42


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?