First published: Thu Jun 03 2004(Updated: )
cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the SCRIPT_FILENAME variable to find and execute a script instead of the PATH_TRANSLATED variable, which allows local users to execute arbitrary PHP code as other users via a URL that references the attacker's script after the user's script, which executes the attacker's script with the user's privileges, a different vulnerability than CVE-2004-0529.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cpanel Cpanel | =9.0 | |
Cpanel Cpanel | =6.4 | |
Cpanel Cpanel | =5.3 | |
Cpanel Cpanel | =9.1.0_r85 | |
Cpanel Cpanel | =5.0 | |
Cpanel Cpanel | =6.0 | |
Cpanel Cpanel | =6.4.1 | |
Cpanel Cpanel | =6.4.2_stable_48 | |
Cpanel Cpanel | =6.4.2 | |
Cpanel Cpanel | =8.0 | |
Cpanel Cpanel | =9.1 | |
Cpanel Cpanel | =6.2 | |
Cpanel Cpanel | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.