CVE-2004-1604: Medium severity Cpanel Cpanel vulnerability
cPanel 9.9.1-RELEASE-3 allows remote authenticated users to chmod arbitrary files via a symlink attack on the private directory, which is created when Front Page extensions are enabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1604?
CVE-2004-1604 is considered a medium severity vulnerability due to its potential for unauthorized file permissions modification.
How do I fix CVE-2004-1604?
To fix CVE-2004-1604, update cPanel to a version that does not allow this vulnerability, preferably a later version than 9.9.1-RELEASE-3.
Who is affected by CVE-2004-1604?
Remote authenticated users with access to cPanel 9.9.1-RELEASE-3 may exploit CVE-2004-1604 to change permissions on arbitrary files.
What attack vector is used in CVE-2004-1604?
CVE-2004-1604 is exploited through a symlink attack targeting the _private directory in cPanel.
What are the potential consequences of exploiting CVE-2004-1604?
Exploitation of CVE-2004-1604 can lead to unauthorized file access and modification, posing security risks to the affected system.