VOOZH about

URL: https://www.kb.cert.org/vuls/id/584089

⇱ VU#584089 - cPanel XSRF vulnerabilities


CERT Coordination Center

cPanel XSRF vulnerabilities

Vulnerability Note VU#584089

Original Release Date: 2008-04-30 | Last Revised: 2008-07-30

Overview

cPanel contains multiple cross-site request forgery (XSRF) vulnerabilities. If successfully exploited, these vulnerabilities may allow an attacker to execute arbitrary commands.

Description

cPanel, a web-based tool that is designed to automate and control web sites and servers, contains multiple cross-site request forgery () vulnerabilities. These vulnerabilities may be triggered by a remote attacker who convinces an administrator to browse to a malicious website while logged into their cPanel account.

Impact

An attacker may be able to perform actions that only authorized administrators should be able to execute.

Solution

We are currently unaware of a practical solution to this problem.

Enable referrer checking

Referrer checking may mitigate some XSRF attacks. To enable referrer checking, follow the steps below. Note that referrer checking may cause some applications to fail.

  1. Navigate to
  2. Go to
  3. Go to
  4. Check the box and save the page

Do not browse to untrusted sites

Administrators can mitigate XSRF vulnerabilities in cPanel and other browser-based tools by not browsing to untrusted websites while logged into their account.

Vendor Information

584089

cPanel Inc. Affected

Notified:  April 22, 2008 Updated: April 28, 2008

Status

Affected

Vendor Statement

We have not received a statement from the vendor.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

Thanks to Michael Brooks for information that was used in this report.

This document was written by Ryan Giobbi.

Other Information

CVE IDs: CVE-2008-2043
Severity Metric: 2.25
Date Public: 2008-04-17
Date First Published: 2008-04-30
Date Last Updated: 2008-07-30 19:10 UTC
Document Revision: 21

Sponsored by CISA.

Download PGP Key

Read CERT/CC Blog

Learn about Vulnerability Analysis

Carnegie Mellon University
Software Engineering Institute
4500 Fifth Avenue
Pittsburgh, PA 15213-2612
412-268-5800

©2022 Carnegie Mellon University
Contact SEI

Contact CERT/CC

412-268-5800
cert@cert.org