{"api_version":"1","generated_at":"2026-07-23T07:35:57+00:00","cve":"CVE-2004-1603","urls":{"html":"https://cve.report/CVE-2004-1603","api":"https://cve.report/api/cve/CVE-2004-1603.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-1603","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-1603"},"summary":{"title":"CVE-2004-1603","description":"cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-10-18 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-59","n/a"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"5.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/11449","name":"http://www.securityfocus.com/bid/11449","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Exploit","Patch","Third Party Advisory","VDB Entry","Vendor Advisory"],"title":"cPanel Remote Backup Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17780","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17780","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/12865","name":"http://secunia.com/advisories/12865","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Exploit","Patch","Vendor Advisory"],"title":"Secunia - Advisories - cPanel Manipulation and Disclosure of Sensitive information Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17779","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17779","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=109811572123753&w=2","name":"http://marc.info/?l=bugtraq&m=109811572123753&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/11455","name":"http://www.securityfocus.com/bid/11455","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Exploit","Patch","Third Party Advisory","VDB Entry","Vendor Advisory"],"title":"cPanel Front Page Extension Installation File Ownership Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://marc.info/?l=bugtraq&m=109811654104208&w=2","name":"http://marc.info/?l=bugtraq&m=109811654104208&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-1603","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-1603","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"1603","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cpanel","cpe5":"cpanel","cpe6":"9.4.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T01:00:36.711Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"cpanel-htaccess-modify-ownership(17780)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17780"},{"name":"20041018 cPanel hardlink backup issue","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=109811572123753&w=2"},{"name":"cpanel-backup-view-file(17779)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17779"},{"name":"20041018 cPanel hardlink chown issue","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=109811654104208&w=2"},{"name":"11455","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/11455"},{"name":"12865","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/12865"},{"name":"11449","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/11449"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-10-18T00:00:00.000Z","descriptions":[{"lang":"en","value":"cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"cpanel-htaccess-modify-ownership(17780)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17780"},{"name":"20041018 cPanel hardlink backup issue","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=109811572123753&w=2"},{"name":"cpanel-backup-view-file(17779)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17779"},{"name":"20041018 cPanel hardlink chown issue","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=109811654104208&w=2"},{"name":"11455","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/11455"},{"name":"12865","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/12865"},{"name":"11449","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/11449"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-1603","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"cpanel-htaccess-modify-ownership(17780)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17780"},{"name":"20041018 cPanel hardlink backup issue","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=109811572123753&w=2"},{"name":"cpanel-backup-view-file(17779)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17779"},{"name":"20041018 cPanel hardlink chown issue","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=109811654104208&w=2"},{"name":"11455","refsource":"BID","url":"http://www.securityfocus.com/bid/11455"},{"name":"12865","refsource":"SECUNIA","url":"http://secunia.com/advisories/12865"},{"name":"11449","refsource":"BID","url":"http://www.securityfocus.com/bid/11449"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-1603","datePublished":"2005-02-20T05:00:00.000Z","dateReserved":"2005-02-20T00:00:00.000Z","dateUpdated":"2024-08-08T01:00:36.711Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-10-18 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-59","n/a"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:cpanel:cpanel:9.4.1:*:*:*:*:*:*:*","matchCriteriaId":"AFF1B164-A4F9-4291-B25E-1FDFCE0A4E78"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"1603","Ordinal":"1","Title":"CVE-2004-1603","CVE":"CVE-2004-1603","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"1603","Ordinal":"1","NoteData":"cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled.","Type":"Description","Title":"CVE-2004-1603"},{"CveYear":"2004","CveId":"1603","Ordinal":"2","NoteData":"2005-02-20","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"1603","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}