| |||||||||||||
| CVE ID: | CVE-2004-1420 |
| Description: | Multiple cross-site scripting (XSS) vulnerabilities in header.php in WHM AutoPilot 2.4.6.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) site_title or (2) http_images parameter. |
| Test IDs: | None available |
| Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2004-1420 Bugtraq: 20041228 Multiple WHM Autopilot Vulnerabilities (Google Search) http://marc.theaimsgroup.com/?l=bugtraq&m=110425620105529&w=2 http://www.gulftech.org/?node=research&article_id=00059-12272004 Bugtraq: 20041231 WHM AutoPilot Security Release [ Plus Upgrade Instructions ] (Google Search) http://marc.theaimsgroup.com/?l=bugtraq&m=110451997904494&w=2 BugTraq ID: 12119 http://www.securityfocus.com/bid/12119 http://secunia.com/advisories/13673 XForce ISS Database: whm-autopilot-header-xss(18700) http://xforce.iss.net/xforce/xfdb/18700 |
|