
在 cPanel 的某些版本中发现了一个可利用的反射型跨站脚本(XSS)漏洞,并分配了编号 CVE-2023-29489。该漏洞允许攻击者在无需认证的情况下执行任意 JavaScript 代码。即使 cPanel 管理端口未对外暴露,该 XSS 漏洞仍可能被利用。如果网站由 cPanel 管理,则 80 和 443 端口上的网站也容易受到此漏洞的影响。
在 cPanel 11.109.9999.116 之前版本中发现了一个问题。通过无效的 webcall ID,跨站脚本可能会在 cpsrvd 错误页面上发生。
pip install CVE-2023-29489
CVE-2023-29489 -h
v1.0
_______ ________ ___ ____ ___ ___ ___ ________________
/ ____/ | / / ____/ |__ \ / __ \__ \|__ \ |__ \< /__ /__ < /
/ / | | / / __/________/ // / / /_/ /__/ /_______/ // / /_ < / // /
/ /___ | |/ / /__/_____/ __// /_/ / __// __/_____/ __// /___/ / / // /
\____/ |___/_____/ /____/\____/____/____/ /____/_//____/ /_//_/
Developed By https://cappriciosec.com
CVE-2022-21371 : Bug scanner for WebPentesters and Bugbounty Hunters
$ CVE-2022-21371 [option]
Usage: CVE-2022-21371 [options]
Options:
-u, --url URL to scan CVE-2022-21371 -u https://target.com
-i, --input <filename> Read input from txt CVE-2022-21371 -i target.txt
-o, --output <filename> Write output in txt file CVE-2022-21371 -i target.txt -o output.txt
-c, --chatid Creating Telegram Notification CVE-2022-21371 --chatid yourid
-b, --blog To Read about CVE-2022-21371 Bug CVE-2022-21371 -b
-h, --help Help Menu
网站 : https://cappriciosec.com/
邮箱 : [email protected]
| 选项 | 描述 | 示例 |
|---|
| -u, --url | 要扫描的 URL | CVE-2023-29489 -u https://target.com |
| -i, --input | 从 txt 文件读取输入 | CVE-2023-29489 -i target.txt |
| -o, --output | 将输出写入 txt 文件 | CVE-2023-29489 -i target.txt -o output.txt |
| -c, --chatid | 创建 Telegram 通知 | CVE-2023-29489 --chatid yourid |
| -b, --blog | 阅读关于 CVE-2023-29489 漏洞的信息 | CVE-2023-29489 -b |
| -h, --help | 帮助菜单 |