VulnerabilityModified
CVE-2004-1603
cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled.
MEDIUM 5.5EPSS 1.64%
Does this matter?
Lower severity and a low EPSS score (1.64%). Track it; it rarely justifies an emergency change on its own.
Description
cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.64% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-59
- Affected
- cpanel/cpanel
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=109811572123753&w=2Mailing List
- http://marc.info/?l=bugtraq&m=109811654104208&w=2Mailing List
- http://secunia.com/advisories/12865Broken Link, Exploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/11449Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.securityfocus.com/bid/11455Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17779Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17780Third Party Advisory, VDB Entry
- http://marc.info/?l=bugtraq&m=109811572123753&w=2Mailing List
- http://marc.info/?l=bugtraq&m=109811654104208&w=2Mailing List
- http://secunia.com/advisories/12865Broken Link, Exploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/11449Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.securityfocus.com/bid/11455Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17779Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17780Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.