Multiple CPanel Perl Script Failure To Implement Taint Mode Weakness
BID:10479
Info
Multiple CPanel Perl Script Failure To Implement Taint Mode Weakness
| Bugtraq ID: | 10479 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 07 2004 12:00AM |
| Updated: | Jun 07 2004 12:00AM |
| Credit: | Discovery of this weakness is credited to Rob Brown <[email protected]>. |
| Vulnerable: |
cPanel cPanel 9.1 .0-R85 cPanel cPanel 9.1 cPanel cPanel 9.0 cPanel cPanel 8.0 cPanel cPanel 7.0 cPanel cPanel 6.4.2 .STABLE_48 cPanel cPanel 6.4.2 cPanel cPanel 6.4.1 cPanel cPanel 6.4 cPanel cPanel 6.2 cPanel cPanel 6.0 cPanel cPanel 5.3 cPanel cPanel 5.0 |
| Not Vulnerable: | |
Discussion
Multiple CPanel Perl Script Failure To Implement Taint Mode Weakness
Multiple Perl scripts that are distributed with cPanel are reported prone to a security weakness. The issues are reported to exist because the scripts do not run with taint mode. These weaknesses may be exploited in conjunction with the weakness described in BID 10478 in order to elevate privileges on a vulnerable system.
Multiple Perl scripts that are distributed with cPanel are reported prone to a security weakness. The issues are reported to exist because the scripts do not run with taint mode. These weaknesses may be exploited in conjunction with the weakness described in BID 10478 in order to elevate privileges on a vulnerable system.
Exploit / POC
Multiple CPanel Perl Script Failure To Implement Taint Mode Weakness
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Multiple CPanel Perl Script Failure To Implement Taint Mode Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Multiple CPanel Perl Script Failure To Implement Taint Mode Weakness
References:
References:
- cPanel Homepage (cPanel)
- cPanel mod_php suEXEC Taint Vulnerability (Rob Brown
)