10
CVSSv2

CVE-2004-1770

Published: 11/03/2004 Updated: 11/07/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The login page for cPanel 9.1.0, and possibly other versions, allows remote malicious users to execute arbitrary code via shell metacharacters in the user parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

cpanel cpanel 5.0

cpanel cpanel 5.3

cpanel cpanel 7.0

cpanel cpanel 8.0

cpanel cpanel 6.4

cpanel cpanel 6.4.1

cpanel cpanel 6.0

cpanel cpanel 6.2

cpanel cpanel 9.0

cpanel cpanel 9.1

cpanel cpanel 6.4.2

cpanel cpanel 6.4.2_stable_48

Exploits

source: wwwsecurityfocuscom/bid/9855/info A potential remote command execution vulnerability has been discovered in the cPanel application This issue occurs due to insufficient sanitization of externally supplied data to the login script An attacker may exploit this problem by crafting a malicious URI request for the affected script; th ...