cancel_account.php in WHM AutoPilot 2.5.30 and earlier allows remote attackers to cancel requests for arbitrary accounts via a modified c parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Whm_autopilot | Whm_autopilot | 2.4.5 (including) | 2.4.5 (including) |
Whm_autopilot | Whm_autopilot | 2.4.6 (including) | 2.4.6 (including) |
Whm_autopilot | Whm_autopilot | 2.4.6.5 (including) | 2.4.6.5 (including) |
Whm_autopilot | Whm_autopilot | 2.4.7 (including) | 2.4.7 (including) |
Whm_autopilot | Whm_autopilot | 2.5.0 (including) | 2.5.0 (including) |
Whm_autopilot | Whm_autopilot | 2.5.20 (including) | 2.5.20 (including) |