cPanel Openwebmail Local Privileges Escalation Vulnerability
BID:6885
Info
cPanel Openwebmail Local Privileges Escalation Vulnerability
| Bugtraq ID: | 6885 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 19 2003 12:00AM |
| Updated: | Feb 19 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to: pokleyzz <[email protected]>. |
| Vulnerable: |
cPanel cPanel 5.0 |
| Not Vulnerable: | |
Discussion
cPanel Openwebmail Local Privileges Escalation Vulnerability
It has been reported that cPanels' openwebmail package, distributed as part of the cPanel CGI application, is vulnerable to an external file include vulnerability. Exploitation of this issue may result in local user privilage escalation.
By manipulating environment variables a local attacker may supply, as an include file, an arbitrary local perl-script. This may make it possible to execute the included script with the rights of the openwebmail 'oom' script, which is by default setuid root.
This vulnerability has been reported to affect cPanel version 5 however, previous versions may also be affected.
It has been reported that cPanels' openwebmail package, distributed as part of the cPanel CGI application, is vulnerable to an external file include vulnerability. Exploitation of this issue may result in local user privilage escalation.
By manipulating environment variables a local attacker may supply, as an include file, an arbitrary local perl-script. This may make it possible to execute the included script with the rights of the openwebmail 'oom' script, which is by default setuid root.
This vulnerability has been reported to affect cPanel version 5 however, previous versions may also be affected.
Exploit / POC
cPanel Openwebmail Local Privileges Escalation Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
cPanel Openwebmail Local Privileges Escalation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
cPanel Openwebmail Local Privileges Escalation Vulnerability
References:
References: