CVE-2016-10771: Input Validation
Published Aug 5, 2019
·Updated
cPanel before 60.0.25 allows file-create and file-chmod operations during ModSecurity Audit logfile processing (SEC-165).
Affected Software
4 affected components
Cpanel Cpanel>=11.54.0.0<11.54.0.33
Cpanel Cpanel>=55.9999.61<56.0.39
Cpanel Cpanel>=57.9999.48<58.0.37
Cpanel Cpanel>=59.9999.58<60.0.25
Event History
Aug 5, 2019
CVE Published
via MITRE·12:55 PM
Data Sourced
via MITRE·12:55 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10771?
CVE-2016-10771 is classified as a moderate severity vulnerability affecting cPanel versions earlier than 60.0.25.
2
How do I fix CVE-2016-10771?
To remediate CVE-2016-10771, upgrade cPanel to version 60.0.25 or later.
3
What operations are affected by CVE-2016-10771?
CVE-2016-10771 allows unauthorized file-create and file-chmod operations during ModSecurity Audit logfile processing.
4
Which versions of cPanel are vulnerable to CVE-2016-10771?
CVE-2016-10771 affects cPanel versions before 60.0.25, specifically versions 55.9999.61 through 56.0.39, 57.9999.48 through 58.0.37, and 59.9999.58 through 60.0.25.
5
What is ModSecurity in relation to CVE-2016-10771?
ModSecurity is a web application firewall that is exploited in CVE-2016-10771, allowing insecure operations when processing audit logfiles.