Use of Externally-Controlled Format String
CVE-2016-10773
Summary
cPanel before 60.0.25 allows format-string injection in exception-message handling (SEC-171).
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- LOW
- HIGH
- HIGH
CWE-134 - Use of Externally-Controlled Format String
The software uses a function that accepts a format string as an argument, but the format string originates from an external source.
References
Advisory Timeline
- Published