Quantcast
Channel: Cpanel – Linux – e-diary
Viewing all articles
Browse latest Browse all 12

External XML entity injection in WHM locale upload interface.

$
0
0

The WHM/cPanel XML locale file uploads allowed the processing of external XML entities. This would permit resellers with the ‘locale-edit’ ACL to read any files on the system, make arbitrary network connections, and can also DoS the server with the billion laughs attack.

Fixed Version:
This issue is resolved in the following builds:

11.42.0.23
11.40.1.13
11.38.2.23

cPanel rewarded me $1000 for reporting this vulnerability :)

The post External XML entity injection in WHM locale upload interface. appeared first on Linux - e-diary.


Viewing all articles
Browse latest Browse all 12

Latest Images

Trending Articles



Latest Images