7.2
CVSSv2

CVE-2004-0490

Published: 18/08/2004 Updated: 11/07/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the SCRIPT_FILENAME variable to find and execute a script instead of the PATH_TRANSLATED variable, which allows local users to execute arbitrary PHP code as other users via a URL that references the attacker's script after the user's script, which executes the attacker's script with the user's privileges, a different vulnerability than CVE-2004-0529.

Vulnerable Product Search on Vulmon Subscribe to Product

cpanel cpanel 5.3

cpanel cpanel 6.0

cpanel cpanel 9.0

cpanel cpanel 9.1

cpanel cpanel 6.4.1

cpanel cpanel 6.4.2

cpanel cpanel 6.2

cpanel cpanel 6.4

cpanel cpanel 9.1.0_r85

cpanel cpanel 5.0

cpanel cpanel 6.4.2_stable_48

cpanel cpanel 7.0

cpanel cpanel 8.0

Exploits

source: wwwsecurityfocuscom/bid/10407/info cPanel is reported prone to a privilege escalation vulnerability It is reported that the options used by cPanel to compile Apache 1329 and PHP using the mod_phpsuexec option are insecure These settings will reportedly permit a local attacker to execute arbitrary code as any user who possesses ...