cPanel Local Privilege Escalation Vulnerability
BID:10407
Info
cPanel Local Privilege Escalation Vulnerability
| Bugtraq ID: | 10407 |
| Class: | Design Error |
| CVE: |
CVE-2004-0490 |
| Remote: | No |
| Local: | Yes |
| Published: | May 24 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | Discovery of this vulnerability is credited to Rob Brown <[email protected]>. |
| Vulnerable: |
cPanel cPanel 9.1 .0-R85 cPanel cPanel 9.1 cPanel cPanel 9.0 cPanel cPanel 8.0 cPanel cPanel 7.0 cPanel cPanel 6.4.2 .STABLE_48 cPanel cPanel 6.4.2 cPanel cPanel 6.4.1 cPanel cPanel 6.4 cPanel cPanel 6.2 cPanel cPanel 6.0 cPanel cPanel 5.3 cPanel cPanel 5.0 |
| Not Vulnerable: | |
Discussion
cPanel Local Privilege Escalation Vulnerability
cPanel is reported prone to a privilege escalation vulnerability. It is reported that the options used by cPanel to compile Apache 1.3.29 and PHP using the mod_phpsuexec option are insecure. These settings will reportedly permit a local attacker to execute arbitrary code as any user who possesses a PHP file that is published to the Apache web server.
cPanel is reported prone to a privilege escalation vulnerability. It is reported that the options used by cPanel to compile Apache 1.3.29 and PHP using the mod_phpsuexec option are insecure. These settings will reportedly permit a local attacker to execute arbitrary code as any user who possesses a PHP file that is published to the Apache web server.
Exploit / POC
cPanel Local Privilege Escalation Vulnerability
The following proof of concept is available:
PATH_TRANSLATED=/gone.php
SCRIPT_FILENAME=/usr/local/cpanel/base/frontend/default/phpinfo.php
/usr/bin/php
If the above results in a "No input file specified." message then the system is vulnerable.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
The following proof of concept is available:
PATH_TRANSLATED=/gone.php
SCRIPT_FILENAME=/usr/local/cpanel/base/frontend/default/phpinfo.php
/usr/bin/php
If the above results in a "No input file specified." message then the system is vulnerable.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
cPanel Local Privilege Escalation Vulnerability
Solution:
It is reported that cPanel has addressed this issue. Customers are advised to contact the vendor for further details regarding obtaining and applying fixes. It is reported that only Apache configurations compiled before April 15, 2004 are vulnerable.
Solution:
It is reported that cPanel has addressed this issue. Customers are advised to contact the vendor for further details regarding obtaining and applying fixes. It is reported that only Apache configurations compiled before April 15, 2004 are vulnerable.
References
cPanel Local Privilege Escalation Vulnerability
References:
References:
- cPanel mod_phpsuexec Vulnerability (Rob Brown
)