← back
CVE-2004-1875

CVE-2004-1875

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 4.6%
from disclosure to weapon556 days
Published on NVDMay 10
1st PoC+556d
exploitation probability
4.6%top 9% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0-R85 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to testfile.html, (2) file parameter to erredit.html, (3) dns parameter to dnslook.html, (4) account parameter to ignorelist.html, (5) account parameter to showlog.html, (6) db parameter to repairdb.html, (7) login parameter to doaddftp.html (8) account parameter to editmsg.htm, or (9) ip parameter to del.html. NOTE: the dnslook.html vector was later reported to exist in cPanel 10.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.