First published: Mon Oct 18 2004(Updated: )
cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cpanel Cpanel | =9.4.1_r64 | |
Cpanel Cpanel | =9.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1603 is considered a high severity vulnerability due to its potential for local users to access and modify sensitive files.
To fix CVE-2004-1603, it is recommended to update to a patched version of cPanel that addresses this vulnerability.
The risks associated with CVE-2004-1603 include unauthorized access to files and changes to file ownership which could compromise the integrity of the system.
CVE-2004-1603 affects cPanel version 9.4.1-RELEASE-64 and earlier versions.
CVE-2004-1603 cannot be exploited remotely; it requires local user access to the affected system.