First published: Thu Sep 30 2004(Updated: )
cPanel 9.9.1-RELEASE-3 allows remote authenticated users to chmod arbitrary files via a symlink attack on the _private directory, which is created when Front Page extensions are enabled.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
cPanel | =9.9.1_r3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1604 is considered a medium severity vulnerability due to its potential for unauthorized file permissions modification.
To fix CVE-2004-1604, update cPanel to a version that does not allow this vulnerability, preferably a later version than 9.9.1-RELEASE-3.
Remote authenticated users with access to cPanel 9.9.1-RELEASE-3 may exploit CVE-2004-1604 to change permissions on arbitrary files.
CVE-2004-1604 is exploited through a symlink attack targeting the _private directory in cPanel.
Exploitation of CVE-2004-1604 can lead to unauthorized file access and modification, posing security risks to the affected system.