AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2008-2070

MEDIUM · CVSS 4.3 EPSS 2.18%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2008-05-12 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2008-2070
Severity
MEDIUM
CVSS
4.3
EPSS
2.18%

Original NVD Description

The WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allows remote attackers to bypass XSS protection and inject arbitrary script or HTML via repeated, improperly-ordered "<" and ">" characters in the (1) issue parameter to scripts2/knowlegebase, (2) user parameter to scripts2/changeip, (3) search parameter to scripts2/listaccts, and other unspecified vectors.