OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: XSS in cPanel 11.x

morin.joshgmail.com
Date: Mon Mar 24 2008 - 10:41:35 CDT


Hello,
Is this internal or external thus do you need to be logged in? I tested external/internal and nothing it appears to just dump it out as a missing directory or manpage.

"Could not open /usr/man/man3/%3Cscript%3Ealert(LeZr)%3C/script%3E.3"

Also I believe you meant to place x3 instead of x after frontend? if not it still just says manpage not found.

I tested this out on 11.18.3-STABLE build 21703.

Regards
Joshua