CVE-2004-1770: Critical severity Cpanel Cpanel vulnerability
Published Mar 11, 2004
·Updated
The login page for cPanel 9.1.0, and possibly other versions, allows remote attackers to execute arbitrary code via shell metacharacters in the user parameter.
Affected Software
12 affected components
Cpanel Cpanel=9.0
Cpanel Cpanel=6.4
Cpanel Cpanel=5.3
Cpanel Cpanel=5.0
Cpanel Cpanel=6.0
Cpanel Cpanel=6.4.1
Cpanel Cpanel=6.4.2_stable_48
Cpanel Cpanel=6.4.2
Cpanel Cpanel=8.0
Cpanel Cpanel=9.1
Cpanel Cpanel=6.2
Cpanel Cpanel=7.0
Remediation
Patch Available
Event History
Mar 11, 2004
CVE Published
05:00 AM
Mar 10, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1770?
CVE-2004-1770 is considered a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2004-1770?
To fix CVE-2004-1770, upgrade to a patched version of cPanel that addresses this vulnerability.
3
Which versions are affected by CVE-2004-1770?
CVE-2004-1770 affects cPanel versions 5.0 to 9.1, with the vulnerability being specifically reported in cPanel 9.1.0.
4
What type of attacks can CVE-2004-1770 enable?
CVE-2004-1770 can enable remote attackers to execute arbitrary code on the server.
5
Is user input involved in CVE-2004-1770?
Yes, CVE-2004-1770 exploits the user parameter in the login page, allowing for the injection of shell metacharacters.