CVE-2003-0521
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/08/2003
Last modified:
03/04/2025
Description
Cross-site scripting (XSS) vulnerability in cPanel 6.4.2 allows remote attackers to insert arbitrary HTML and possibly gain cPanel administrator privileges via script in a URL that is logged but not properly quoted when displayed via the (1) Error Log or (2) Latest Visitors screens.
Impact
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:cpanel:cpanel:5.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:cpanel:cpanel:5.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:cpanel:cpanel:6.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:cpanel:cpanel:6.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:cpanel:cpanel:6.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:cpanel:cpanel:6.4.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:cpanel:cpanel:6.4.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:cpanel:cpanel:6.4.2_stable_48:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page