CVE-2005-1932
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/07/2005
Last modified:
03/04/2025
Description
Lpanel 1.59 and earlier, and other versions before 1.597, allows remote authenticated users to modify certain critical variables and (1) modify DNS settings for arbitrary domains via the domain parameter to diagnose.php, (2) close, open, or respond to arbitrary support tickets via the close, open, or pid parameter to view_ticket.php, (3) obtain sensitive information on arbitrary invoices via the inv parameter to viewreceipt.php, or (4) modify domain information for arbitrary domains via the editdomain parameter to domains.php.
Impact
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:lpanel:lpanel:1.59:*:*:*:*:*:*:* | ||
cpe:2.3:a:lpanel:lpanel:1.593:*:*:*:*:*:*:* | ||
cpe:2.3:a:lpanel:lpanel:1.594:*:*:*:*:*:*:* | ||
cpe:2.3:a:lpanel:lpanel:1.596:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034414.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034415.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034416.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034417.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034418.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034419.html
- http://secunia.com/advisories/15589/
- http://www.lpanel.net/changelog.php
- http://www.securityfocus.com/bid/13869
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034414.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034415.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034416.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034417.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034418.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034419.html
- http://secunia.com/advisories/15589/
- http://www.lpanel.net/changelog.php
- http://www.securityfocus.com/bid/13869