CVE-2004-1603: Medium severity Cpanel Cpanel vulnerability
cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1603?
CVE-2004-1603 is considered a high severity vulnerability due to its potential for local users to access and modify sensitive files.
How do I fix CVE-2004-1603?
To fix CVE-2004-1603, it is recommended to update to a patched version of cPanel that addresses this vulnerability.
What are the risks associated with CVE-2004-1603?
The risks associated with CVE-2004-1603 include unauthorized access to files and changes to file ownership which could compromise the integrity of the system.
Which versions of cPanel are affected by CVE-2004-1603?
CVE-2004-1603 affects cPanel version 9.4.1-RELEASE-64 and earlier versions.
Can CVE-2004-1603 be exploited remotely?
CVE-2004-1603 cannot be exploited remotely; it requires local user access to the affected system.