ClueCentral Apache Suexec Patch Security Weakness

BID:10478

Info

ClueCentral Apache Suexec Patch Security Weakness

Bugtraq ID: 10478
Class: Access Validation Error
CVE:
Remote: No
Local: Yes
Published: Jun 07 2004 12:00AM
Updated: Jun 07 2004 12:00AM
Credit: Discovery of this weakness is credited to Rob Brown <[email protected]>.
Vulnerable: cluecentral suexec.patch
+ cPanel cPanel 9.1 .0-R85
+ cPanel cPanel 9.1
+ cPanel cPanel 9.0
+ cPanel cPanel 8.0
+ cPanel cPanel 7.0
+ cPanel cPanel 6.4.2 .STABLE_48
+ cPanel cPanel 6.4.2
+ cPanel cPanel 6.4.1
+ cPanel cPanel 6.4
+ cPanel cPanel 6.2
+ cPanel cPanel 6.0
+ cPanel cPanel 5.3
+ cPanel cPanel 5.0
Not Vulnerable:

Discussion

ClueCentral Apache Suexec Patch Security Weakness

cluecentral Apache suexec patch is reported prone to a local security weakness. It is reported that the patch that is applied to Apache suexec makes suexec insecure. The patch reportedly removes security checks on insecure directory permissions and permits the execution of files owned by arbitrary users, by the 'nobody' user.

A local attacker who has permissions to create, publish and request PHP web content on the affected system may exploit this weakness in conjunction with other security vulnerabilities to achieve some degree of privilege escalation.

Exploit / POC

ClueCentral Apache Suexec Patch Security Weakness

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

ClueCentral Apache Suexec Patch Security Weakness

Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

References

ClueCentral Apache Suexec Patch Security Weakness

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report