cPanel Killacct Script Customer Account DNS Information Deletion Vulnerability
BID:10468
Info
cPanel Killacct Script Customer Account DNS Information Deletion Vulnerability
| Bugtraq ID: | 10468 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 05 2004 12:00AM |
| Updated: | Jun 05 2004 12:00AM |
| Credit: | Discovery is credited to qbann targ <[email protected]>. |
| Vulnerable: |
cPanel cPanel 9.1 .0-R85 cPanel cPanel 9.1 cPanel cPanel 9.0 cPanel cPanel 8.0 cPanel cPanel 7.0 cPanel cPanel 6.4.2 .STABLE_48 cPanel cPanel 6.4.2 cPanel cPanel 6.4.1 cPanel cPanel 6.4 cPanel cPanel 6.2 cPanel cPanel 6.0 cPanel cPanel 5.3 cPanel cPanel 5.0 |
| Not Vulnerable: | |
Discussion
cPanel Killacct Script Customer Account DNS Information Deletion Vulnerability
cPanel is prone to a vulnerability that can allow a remote authenticated administrator to delete customer account DNS information for customers that are not administered by that administrator. This attack can allow an attacker to cause a denial of service condition against vulnerable Web sites.
cPanel is prone to a vulnerability that can allow a remote authenticated administrator to delete customer account DNS information for customers that are not administered by that administrator. This attack can allow an attacker to cause a denial of service condition against vulnerable Web sites.
Exploit / POC
cPanel Killacct Script Customer Account DNS Information Deletion Vulnerability
No exploit is required.
The following proof of concept is available:
http://www.example.com:2086/scripts/killacct?domain=(domain)&user=(user)&submit-domain=Terminate
No exploit is required.
The following proof of concept is available:
http://www.example.com:2086/scripts/killacct?domain=(domain)&user=(user)&submit-domain=Terminate
Solution / Fix
cPanel Killacct Script Customer Account DNS Information Deletion Vulnerability
Solution:
The vulnerability described in this BID is reported to be addressed in the latest cPanel RELEASE (current). Customers are advised to contact the vendor for further information regarding obtaining and installing RELEASE builds.
Solution:
The vulnerability described in this BID is reported to be addressed in the latest cPanel RELEASE (current). Customers are advised to contact the vendor for further information regarding obtaining and installing RELEASE builds.
References
cPanel Killacct Script Customer Account DNS Information Deletion Vulnerability
References:
References:
- Another cpanel vuln? (WebHostingTalk Forums)
- cPanel 'killacct' May Let Remote Authenticated Administrators Delete Accounts (SecurityTracker)
- cPanel Homepage (cPanel)