CVE-2004-1769
Summary
| CVE | CVE-2004-1769 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-03-11 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x, allows remote attackers to execute arbitrary code via the user parameter to resetpass. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cpanel | Cpanel | 5.0 | All | All | All |
| Application | Cpanel | Cpanel | 5.3 | All | All | All |
| Application | Cpanel | Cpanel | 6.0 | All | All | All |
| Application | Cpanel | Cpanel | 6.2 | All | All | All |
| Application | Cpanel | Cpanel | 6.4 | All | All | All |
| Application | Cpanel | Cpanel | 6.4.1 | All | All | All |
| Application | Cpanel | Cpanel | 6.4.2 | All | All | All |
| Application | Cpanel | Cpanel | 6.4.2_stable_48 | All | All | All |
| Application | Cpanel | Cpanel | 7.0 | All | All | All |
| Application | Cpanel | Cpanel | 8.0 | All | All | All |
| Application | Cpanel | Cpanel | 9.0 | All | All | All |
| Application | Cpanel | Cpanel | 9.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Secunia - Advisories - cPanel Password Reset Command Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| 'cPanel Secuirty Advisory CPANEL-2004:01-01' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| VU#831534 - cPanel fails to verify input passed to the "user" parameter | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory, US Government Resource |
| cPanel Resetpass Remote Command Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.